CVE-2026-54214
TeamDavid: Header Injection through the 'cType' URL parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because the parameter does not properly restrict control characters such as URL-encoded newlines (“%0a”) or colons, attackers can inject additional headers including extra Location headers into the server’s response. This results e.g. in an open redirect vulnerability. This issue affects TeamDavid through Rollout 524.
| CWE | CWE-601 |
| Vendor | tobit laboratories ag |
| Product | teamdavid |
| Published | Aug 7, 2026 |
| Last Updated | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for tobit laboratories ag teamdavid
Be the first to know when new unknown vulnerabilities affecting tobit laboratories ag teamdavid are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Tobit Laboratories AG / TeamDavid
0 ≤ Rollout 524
References
Credits
Dario Weiss of InfoGuard Labs