{"id":"DEBIAN-CVE-2025-40927","details":"CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for reflected XSS or open redirect under certain conditions.  Although some validation exists, it can be bypassed using URL-encoded values, allowing an attacker to inject untrusted content into the response via query parameters.    As a result, an attacker can inject a line break (e.g. %0A) into the parameter value, causing the server to split the HTTP response and inject arbitrary headers or even an HTML/JavaScript body, leading to reflected cross-site scripting (XSS), open redirect or other attacks.  The issue documented in CVE-2010-4410 https://www.cve.org/CVERecord?id=CVE-2010-4410 is related but the fix was incomplete.  Impact  By injecting %0A (newline) into a query string parameter, an attacker can:    *  Break the current HTTP header   *  Inject a new header or entire body   *  Deliver a script payload that is reflected in the server’s response That can lead to the following attacks:    *  reflected XSS   *  open redirect   *  cache poisoning   *  header manipulation","modified":"2026-09-01T20:05:52.254649729Z","published":"2025-08-29T01:15:34.553Z","upstream":["CVE-2025-40927"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-40927"}],"affected":[{"package":{"name":"libcgi-simple-perl","ecosystem":"Debian:12","purl":"pkg:deb/debian/libcgi-simple-perl?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.280-2+deb12u1"}]}],"versions":["1.280-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-40927.json"}},{"package":{"name":"libcgi-simple-perl","ecosystem":"Debian:13","purl":"pkg:deb/debian/libcgi-simple-perl?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.282-1~deb13u1"}]}],"versions":["1.281-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-40927.json"}},{"package":{"name":"libcgi-simple-perl","ecosystem":"Debian:14","purl":"pkg:deb/debian/libcgi-simple-perl?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.282-1"}]}],"versions":["1.281-1","1.282-1~deb13u1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-40927.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}