{"id":"UBUNTU-CVE-2025-40927","details":"CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for reflected XSS or open redirect under certain conditions. Although some validation exists, it can be bypassed using URL-encoded values, allowing an attacker to inject untrusted content into the response via query parameters. As a result, an attacker can inject a line break (e.g. %0A) into the parameter value, causing the server to split the HTTP response and inject arbitrary headers or even an HTML/JavaScript body, leading to reflected cross-site scripting (XSS), open redirect or other attacks. The issue documented in CVE-2010-4410 https://www.cve.org/CVERecord?id=CVE-2010-4410 is related but the fix was incomplete. Impact By injecting %0A (newline) into a query string parameter, an attacker can:   *  Break the current HTTP header   *  Inject a new header or entire body   *  Deliver a script payload that is reflected in the server’s response That can lead to the following attacks:   *  reflected XSS   *  open redirect   *  cache poisoning   *  header manipulation","modified":"2026-05-20T16:23:24.375744563Z","published":"2025-08-29T01:15:00Z","upstream":["CVE-2025-40927"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-40927"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-40927"},{"type":"REPORT","url":"https://lists.security.metacpan.org/cve-announce/msg/32357435/"},{"type":"REPORT","url":"https://github.com/manwar/CGI--Simple/commit/0c1a2e0b8f24804d33daac686666ac944363a630"},{"type":"REPORT","url":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2320"},{"type":"REPORT","url":"https://datatracker.ietf.org/doc/html/rfc7230#section-3"},{"type":"REPORT","url":"https://metacpan.org/release/MANWAR/CGI-Simple-1.281/diff/MANWAR/CGI-Simple-1.282/lib/CGI/Simple.pm"},{"type":"REPORT","url":"https://metacpan.org/release/MANWAR/CGI-Simple-1.281/source/lib/CGI/Simple.pm#L1031-1035"},{"type":"REPORT","url":"https://owasp.org/www-community/attacks/HTTP_Response_Splitting"},{"type":"REPORT","url":"https://rt.perl.org/Public/Bug/Display.html?id=21951"}],"affected":[{"package":{"name":"libcgi-simple-perl","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/libcgi-simple-perl?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.115-1","1.115-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libcgi-simple-perl","binary_version":"1.115-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-40927.json"}},{"package":{"name":"libcgi-simple-perl","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/libcgi-simple-perl?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.115-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libcgi-simple-perl","binary_version":"1.115-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-40927.json"}},{"package":{"name":"libcgi-simple-perl","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libcgi-simple-perl?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.115-2"],"ecosystem_specific":{"binaries":[{"binary_version":"1.115-2","binary_name":"libcgi-simple-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-40927.json"}},{"package":{"name":"libcgi-simple-perl","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libcgi-simple-perl?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.115-2","1.280-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.280-1","binary_name":"libcgi-simple-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-40927.json"}},{"package":{"name":"libcgi-simple-perl","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libcgi-simple-perl?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.280-2","1.281-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libcgi-simple-perl","binary_version":"1.281-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-40927.json"}},{"package":{"name":"libcgi-simple-perl","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/libcgi-simple-perl?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.281-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.281-1","binary_name":"libcgi-simple-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-40927.json"}},{"package":{"name":"libcgi-simple-perl","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/libcgi-simple-perl?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.281-1","1.282-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.282-1","binary_name":"libcgi-simple-perl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-40927.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"Ubuntu","score":"medium"}]}