CVE-2026-50188: Curlopt Httpheader Crlf Injectioncve-2026-50188-curlopt-httpheader-crlf-injection
Missing sanitization of HTTP header values assigned to CURLOPT_HTTPHEADER can lead to HTTP header injection (CRLF injection). Attackers can inject carriage returns and line feeds to manipulate outgoing HTTP requests.