CVE-2012-5526: Andy Armstrong Cgi.pm
Medium severity, CVSS 5.0. EPSS: 3.3% chance of exploitation in the next 30 days.
CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.
Affected products
- Andy Armstrong Cgi.pm: up to and including 3.62
Published 2012-11-21. Last modified 2026-06-16.