MEDIUM
fbeta-GmbH
CVE published 2026-08-18
CVE-2026-50576
CVE-2026-50576 is a vulnerability in ePA 3.x Integration that allows an authenticated attacker to inject additional headers into inner HTTP requests, potentially exposing patient records or bypassing authentication. The vulnerability arises from the lack of neutralization of CRLF characters in values used to construct VAU inner HTTP requests. This issue is fixed in version 1.3.0. Defenders should prioriti [truncated]