CVE-2026-39915 PUBLISHED

TIM Flow < 26.0.6 CRLF Injection via rt Parameter

Assigner: VulnCheck
Reserved: 07.04.2026 Published: 24.08.2026 Updated: 24.08.2026

TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized carriage return and line feed sequences in the rt URL parameter, which is reflected into Set-Cookie response headers. Attackers can craft malicious requests to induce authenticated users to execute arbitrary JavaScript in their browser context, enabling session token theft and account credential modification.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor TIM Solutions
Product TIM Flow
Versions Default: affected
  • affected from 0 to 26.0.6 (excl.)

Credits

  • William Visée finder

References

Problem Types

  • Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') CWE