CVE-2026-106512 - MISP sachertortephp - CakeResponse::download() HTTP Response Splitting via Unsanitized Filename Enables Stored XSS
CVE ID :CVE-2026-106512 Published : Oct. 6, 2026, 6:48 p.m. | 40 minutes ago Description :The CakeResponse::download() method in lib/Cake/Network/CakeResponse.php constructs a Content-Disposition header by directly interpolating a caller-supplied filename into a quoted-string value without...