{"api_version":"1","generated_at":"2026-07-23T13:11:49+00:00","cve":"CVE-2009-4086","urls":{"html":"https://cve.report/CVE-2009-4086","api":"https://cve.report/api/cve/CVE-2009-4086.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-4086","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-4086"},"summary":{"title":"CVE-2009-4086","description":"CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL.  NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-11-29 13:07:34","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54356","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54356","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36681","name":"http://secunia.com/advisories/36681","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Xerver HTTP Server Security Bypass and Cross-Site Scripting - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.org/0911-exploits/xerver-split.txt","name":"http://packetstormsecurity.org/0911-exploits/xerver-split.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Files ≈ Packet Storm","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/37064","name":"http://www.securityfocus.com/bid/37064","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Xerver HTTP Response Splitting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-4086","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-4086","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"4086","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"javascript","cpe5":"xerver_http_server","cpe6":"4.31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"4086","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"javascript","cpe5":"xerver_http_server","cpe6":"4.32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:54:09.353Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"36681","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36681"},{"name":"xerver-response-splitting(54356)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54356"},{"name":"37064","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/37064"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.org/0911-exploits/xerver-split.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-11-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL.  NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"36681","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36681"},{"name":"xerver-response-splitting(54356)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54356"},{"name":"37064","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/37064"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.org/0911-exploits/xerver-split.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-4086","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL.  NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"36681","refsource":"SECUNIA","url":"http://secunia.com/advisories/36681"},{"name":"xerver-response-splitting(54356)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54356"},{"name":"37064","refsource":"BID","url":"http://www.securityfocus.com/bid/37064"},{"name":"http://packetstormsecurity.org/0911-exploits/xerver-split.txt","refsource":"MISC","url":"http://packetstormsecurity.org/0911-exploits/xerver-split.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-4086","datePublished":"2009-11-27T20:45:00.000Z","dateReserved":"2009-11-27T00:00:00.000Z","dateUpdated":"2024-08-07T06:54:09.353Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-11-29 13:07:34","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:javascript:xerver_http_server:4.31:*:*:*:*:*:*:*","matchCriteriaId":"D836C05E-51D1-4C8D-B06A-E0219E071406"},{"vulnerable":true,"criteria":"cpe:2.3:a:javascript:xerver_http_server:4.32:*:*:*:*:*:*:*","matchCriteriaId":"8DB82675-97C0-4D8E-A1E3-D145C49ECE90"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"4086","Ordinal":"1","Title":"CVE-2009-4086","CVE":"CVE-2009-4086","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"4086","Ordinal":"1","NoteData":"CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL.  NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2009-4086"},{"CveYear":"2009","CveId":"4086","Ordinal":"2","NoteData":"2009-11-27","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"4086","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}