5.3

CVE-2026-44256

Exploit

Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 and 5.0.0-beta2, api/api/middlewares.py decodes the Basic authentication username before credential validation and passes it to the access logger without neutralizing control characters. api/api/alogging.py interpolates that value into the plain-text API log. An unauthenticated attacker can include carriage returns or line feeds in the username to forge entries, obscure activity, or poison systems that consume the plain-text audit log. The JSON log format is not affected because JSON serialization escapes these characters. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wazuh ≫ Wazuh Version >= 4.4.0 < 4.14.6
Wazuh ≫ Wazuh Version 5.0.0 Update beta1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.213
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-117 Improper Output Neutralization for Logs

The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

https://github.com/wazuh/wazuh/releases/tag/v4.14.6
Release Notes
https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta2
Release Notes
https://github.com/wazuh/wazuh/security/advisories/GHSA-c3m6-fp2h-wmr4
Vendor Advisory
Exploit
https://github.com/wazuh/wazuh/pull/35866
Patch
Issue Tracking
https://github.com/wazuh/wazuh/commit/cddf3fd16b0f945b28eb9c27714de3cc344e0926
Patch