CVE-2026-4096EPSS p4.6%

CVE-2026-4096CVE-2026-4096

hcltech / devops_plan

Description

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking

Scoring

CVSS 6.5 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS0.15% probability of exploitation · percentile 4.6% · 2026-08-03T12:00:16Z
Last modified2026-07-27
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.