Intel

AIKIDO-2025-10354

spectator-ext-ipcservlet is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 6, 2025

62

Medium Risk

This Affects:

JAVAspectator-ext-ipcservlet
0.74.0 - 1.8.12
Fixed in 1.8.13
Are you affected? Scan for Free

TL;DR

Affected versions are vulnerable to HTTP header injection due to improper sanitization of carriage return (CR) or line feed (LF) characters in header values. An attacker could exploit this by injecting malicious headers or manipulating the response structure, potentially leading to security issues such as response splitting, cache poisoning, or cross-site scripting in downstream systems.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spectator-ext-ipcservlet is vulnerable to Improper Input Validation in versions 0.74.0 - 1.8.12.

How to fix this

Upgrade the com.netflix.spectator:spectator-ext-ipcservlet library to the patch version.