CVE-2018-25016: Greenbone OS

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.

Affected products

  • Greenbone Greenbone OS: before 5.0.0 (fixed in 5.0.0)
  • Greenbone Greenbone Security Assistant: before 7.0.3 (fixed in 7.0.3)

Published 2021-06-21. Last modified 2026-06-17.