<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Header-Injection — PoC Archive</title><link>https://poc.intelseclab.com/tags/header-injection/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/header-injection/index.xml" rel="self" type="application/rss+xml"/><item><title>Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7. Status: Patched (9.2.15 / 10.1.4). Affects: Apache Traffic Server. Tags: apache, traffic-server, ats, header-injection, metadata-spoof, cache-poisoning, acl-bypass, plugin, CVE-2026-33267.</description><category>web</category><category>Critical</category><category>apache</category><category>traffic-server</category><category>ats</category><category>header-injection</category><category>metadata-spoof</category><category>cache-poisoning</category><category>acl-bypass</category><category>plugin</category><category>CVE-2026-33267</category></item><item><title>CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-31_cve-2022-40684-fortios-auth-bypass-scanner/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-31_cve-2022-40684-fortios-auth-bypass-scanner/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2022-40684. Status: Patched (FortiOS ≥7.2.2, ≥7.0.7; FortiProxy ≥7.2.1, ≥7.0.7; FortiSwitchManager ≥7.2.1). Affects: Fortinet FortiOS (FortiGate firewalls), FortiProxy web proxy, FortiSwitchManager web management interface / administrative REST API. Tags: fortios, fortiproxy, fortiswitchmanager, authentication-bypass, rest-api, header-injection, loopback-spoofing, fortigate, ssl-vpn, scanner.</description><category>network</category><category>Critical</category><category>fortios</category><category>fortiproxy</category><category>fortiswitchmanager</category><category>authentication-bypass</category><category>rest-api</category><category>header-injection</category><category>loopback-spoofing</category><category>fortigate</category><category>ssl-vpn</category><category>scanner</category></item><item><title>camel-coap Header Injection → RCE Self-Contained Reproducer (CVE-2026-33453)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2026-33453-camel-coap-header-injection-reproducer/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2026-33453-camel-coap-header-injection-reproducer/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-33453. Status: Patched. Affects: Apache Camel camel-coap component (org.apache.camel.coap.CamelCoapResource), routes forwarding to camel-exec. Tags: apache-camel, camel-coap, coap, header-injection, rce, cwe-915, camel-exec, unauthenticated, udp, spring-boot.</description><category>web</category><category>Critical</category><category>apache-camel</category><category>camel-coap</category><category>coap</category><category>header-injection</category><category>rce</category><category>cwe-915</category><category>camel-exec</category><category>unauthenticated</category><category>udp</category><category>spring-boot</category></item><item><title>MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42281-magicmirror-cors-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42281-magicmirror-cors-ssrf/</guid><description>Critical severity (CVSS 9.2) — web · CVE-2026-42281. Status: PoC. Affects: MagicMirror². Tags: ssrf, unauthenticated, magicmirror, cloud-metadata, secrets-exfiltration, header-injection, open-proxy, python.</description><category>web</category><category>Critical</category><category>ssrf</category><category>unauthenticated</category><category>magicmirror</category><category>cloud-metadata</category><category>secrets-exfiltration</category><category>header-injection</category><category>open-proxy</category><category>python</category></item><item><title>CRLF Email Header Injection in Plunk via Raw MIME Construction (CVE-2026-34975)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34975-plunk-crlf-email-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34975-plunk-crlf-email-injection/</guid><description>High severity (CVSS 8.5) — web · CVE-2026-34975. Status: PoC. Affects: Plunk (useplunk/plunk). Tags: crlf-injection, email, plunk, mime, header-injection, bcc-injection, cwe-93.</description><category>web</category><category>High</category><category>crlf-injection</category><category>email</category><category>plunk</category><category>mime</category><category>header-injection</category><category>bcc-injection</category><category>cwe-93</category></item><item><title>Apache Camel camel-coap Header Injection to Remote Code Execution (CVE-2026-33453)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33453-apache-camel-coap-header-injection-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33453-apache-camel-coap-header-injection-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-33453. Status: Weaponized. Affects: Apache Camel — camel-coap component (CamelCoapResource), routes forwarding to camel-exec. Tags: apache-camel, coap, header-injection, rce, cwe-915, camel-exec, unauthenticated, udp.</description><category>web</category><category>Critical</category><category>apache-camel</category><category>coap</category><category>header-injection</category><category>rce</category><category>cwe-915</category><category>camel-exec</category><category>unauthenticated</category><category>udp</category></item><item><title>Apache APISIX forward-auth CRLF Header Injection — CVE-2026-31908</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-31908-apisix-crlf-header-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-31908-apisix-crlf-header-injection/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-31908. Status: PoC. Affects: Apache APISIX. Tags: apisix, crlf-injection, header-injection, authentication-bypass, forward-auth, api-gateway, reverse-proxy.</description><category>web</category><category>Critical</category><category>apisix</category><category>crlf-injection</category><category>header-injection</category><category>authentication-bypass</category><category>forward-auth</category><category>api-gateway</category><category>reverse-proxy</category></item><item><title>Next.js Corrupt Middleware Auth Bypass (CVE-2025-29927)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-15_nextjs-middleware-bypass-cve-2025-29927/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-15_nextjs-middleware-bypass-cve-2025-29927/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-29927. Status: Weaponized. Affects: Next.js (Vercel). Tags: auth-bypass, middleware-bypass, Next.js, unauthenticated, header-injection.</description><category>web</category><category>Critical</category><category>auth-bypass</category><category>middleware-bypass</category><category>Next.js</category><category>unauthenticated</category><category>header-injection</category></item></channel></rss>