
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71572 is a response header injection vulnerability in Joomla! CMS download views, classified under security advisory [20260801]. The flaw affects Joomla! versions 3.0.0–5.4.7 and 6.0.0–6.1.2, where a lack of output processing allows CRLF-based header injection in multiple download views, leading to reflected file download and content-type confusion attacks. It was published on August 18, 2026, with a patch made available the same day. The vulnerability carries a CVSS v4.0 base score of 4.8 (Medium) (GitHub Advisory, Joomla Security Centre).
The root cause is improper neutralization of CRLF sequences (CWE-93) in Joomla's download view output handling. Because user-supplied input is not sanitized before being included in HTTP response headers, an attacker can inject arbitrary CRLF sequences to manipulate response headers — a technique known as HTTP response header injection. Exploitation requires High privileges (PR:H) and passive user interaction (UI:P), meaning the attacker must have some elevated access and a victim must interact with a crafted URL. The attack vector is network-based with low complexity and no special attack requirements (GitHub Advisory, Joomla Security Centre).
Successful exploitation allows an attacker to inject malicious HTTP response headers, enabling reflected file download attacks and content-type confusion. This can be leveraged for phishing and social engineering by tricking users into downloading malicious files disguised as legitimate Joomla content. There is no direct confidentiality or availability impact on the vulnerable system itself; the primary risk is low-integrity impact on subsequent systems through spoofed responses (GitHub Advisory, Joomla Security Centre).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The requirement for High privileges further limits the practical attack surface (GitHub Advisory, Joomla Security Centre).
%0d%0a) in a parameter that is reflected into HTTP response headers (e.g., a filename or content-type parameter).Content-Disposition or Content-Type header.%0d%0a, %0D%0A) in query parameters; unusual Content-Disposition or Content-Type headers in server responses.Joomla! has released patches addressing this vulnerability; users should upgrade to versions beyond 5.4.7 (for the 3.x–5.x branch) and beyond 6.1.2 (for the 6.x branch). As interim mitigations, implement strict input validation and output encoding for all download view parameters to prevent CRLF injection. Deploying a Web Application Firewall (WAF) configured to filter CRLF sequences in HTTP request parameters targeting download endpoints can also reduce risk (Joomla Security Centre, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."