CVE-2026-5140

Severity CVSS v4.0:
Pending analysis
Type:
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
Publication date:
29/04/2026
Last modified:
04/05/2026

Description

Improper neutralization of CRLF sequences (&amp;#39;CRLF injection&amp;#39;) vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Authentication Bypass.<br /> <br /> This issue affects Pardus Update: from 0.6.3 before 0.6.4.

References to Advisories, Solutions, and Tools