Executive brief
Kirby is an open-source content management system used to build and manage websites. A vulnerability in its internal HTTP request tool allows attackers to inject unauthorized headers into outgoing requests if the site or a plugin uses untrusted user data in those headers. This could allow an attacker to manipulate how the site communicates with external services, potentially leading to unauthorized access to those services or data tampering.
Technical details
A CRLF (Carriage Return Line Feed) injection vulnerability exists in the Kirby\Http\Remote class, specifically affecting methods like Remote::request(), Remote::get(), and Remote::post(). The root cause is a failure to sanitize newline characters (\r and \n) in header values before they are passed to the underlying cURL implementation. An attacker can exploit this by providing input containing these characters to any application or plugin that forwards user-controlled data into an outgoing request header. This allows the attacker to inject additional headers, potentially bypassing security controls on the remote service, such as Authorization or Host headers. The issue is fixed in versions 4.9.4 and 5.4.4 by stripping line breaks from header values.
Affected products
- getkirby Kirby CMS < 4.9.4, >= 5.0.0, < 5.4.4
Timeline
- 2026-06-17: patched: Fixes released in versions 4.9.4 and 5.4.4
- 2026-06-17: advisory: GitHub Security Advisory published
- 2026-07-09: disclosed: CVE-2026-50188 published to NVD
References
- https://github.com/getkirby/kirby/commit/aa33414e1669e866cdd6f4decfae2a669e8bb828
- https://github.com/getkirby/kirby/commit/fad9cbd22c73ed0fbd3aaf62310a8dcacfc007cd
- https://github.com/getkirby/kirby/releases/tag/4.9.4
- https://github.com/getkirby/kirby/releases/tag/5.4.4
- https://github.com/getkirby/kirby/security/advisories/GHSA-4v4h-m2qq-ppgw