Back

CVE-2002-1405

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.

Published: Feb 19, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (9)

Vendor Product Version
elinks elinks 0.2.4
elinks elinks 0.3.2
links links 0.96
university_of_kansas lynx 2.8.2_rel1
university_of_kansas lynx 2.8.3
university_of_kansas lynx 2.8.3_rel1
university_of_kansas lynx 2.8.4
university_of_kansas lynx 2.8.4_rel1
university_of_kansas lynx 2.8.5_dev8

GitHub Security Advisory GHSA-27fc-4jc3-pjvm

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 5.04%

Top 9% most likely to be exploited

Threat Score 21.5 / 100

Data Sources

NVD EPSS GitHub