Intel

AIKIDO-2026-497041

vrana/adminer is vulnerable to HTTP Response Splitting

HTTP Response SplittingCVE-2026-63771 Published Aug 18, 2026

69

Medium Risk

This Affects:

PHPvrana/adminer
4.6.0 - 5.4.2
Fixed in 5.4.3
Are you affected? Scan for Free

TL;DR

Adminer derives cookie and session paths from REQUEST_URI after prepending the client-influenced X-Forwarded-Prefix header without sanitizing separator characters. Because the tainted value is written directly into the path attribute of manually built Set-Cookie headers, semicolon-separated directives injected through the header become additional cookie attributes. This lets externally controlled input add attributes such as Domain or SameSite to the adminer_sid and adminer_key cookies, downgrading same-site protection and exposing session and key material. The fix escapes and normalizes REQUEST_URI before it is used for cookie and redirect paths.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you forward client-supplied X-Forwarded-Prefix header to Adminer.

Background info

vrana/adminer is vulnerable to HTTP Response Splitting in versions 4.6.0 - 5.4.2.

How to fix this

Upgrade the vrana/adminer library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform