PatchSiren

fbeta-GmbH CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM fbeta-GmbH CVE published 2026-08-18

CVE-2026-50576

CVE-2026-50576 is a vulnerability in ePA 3.x Integration that allows an authenticated attacker to inject additional headers into inner HTTP requests, potentially exposing patient records or bypassing authentication. The vulnerability arises from the lack of neutralization of CRLF characters in values used to construct VAU inner HTTP requests. This issue is fixed in version 1.3.0. Defenders should prioriti [truncated]