CVE-2024-1064: Craftycontrol Crafty Controller

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header

Affected products

  • Craftycontrol Crafty Controller: from 4.0.0, up to and including 4.2.2

Published 2024-02-03. Last modified 2026-06-17.