{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-06T04:37:47.459","vulnerabilities":[{"cve":{"id":"CVE-2026-3234","sourceIdentifier":"secalert@redhat.com","published":"2026-03-12T11:15:57.147","lastModified":"2026-03-12T21:07:53.427","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in  mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeenc() function, allows a remote attacker to bypass input validation. By injecting CRLF sequences into the cluster configuration, an attacker can corrupt the response body of INFO endpoint responses. Exploitation requires network access to the MCMP protocol port, but no authentication is needed."},{"lang":"es","value":"Se encontró un fallo en mod_proxy_cluster. Esta vulnerabilidad, una inyección de Retorno de Carro y Salto de Línea (CRLF) en la función decodeenc(), permite a un atacante remoto eludir la validación de entrada. Al inyectar secuencias CRLF en la configuración del clúster, un atacante puede corromper el cuerpo de la respuesta de las respuestas del endpoint INFO. La explotación requiere acceso de red al puerto del protocolo MCMP, pero no se necesita autenticación."}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Primary","description":[{"lang":"en","value":"CWE-93"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-3234","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2442889","source":"secalert@redhat.com"}]}}]}