HTTP response splitting in Joomla! - CVE-2026-71572
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause reflected file download and content-type confusion.
The vulnerability exists due to improper output neutralization in multiple download views when handling crafted requests. A remote attacker can send a specially crafted request to cause reflected file download and content-type confusion.