AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-0456

LOW · CVSS 2.6 EPSS 19.04%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-01-25 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 2.6. It affects Apache. Its EPSS score suggests a 19.0% probability of exploitation in the next 30 days. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2008-0456
Severity
LOW
CVSS
2.6
EPSS
19.04%
Apache

Original NVD Description

CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.