---
id: CVE-2025-66485
title: >-
  IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection,
  caused by improper validation of input by the HOST headers
summary: "IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. \_This could allow an attacker to conduct various attacks against the vulnerable system, including …"
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-644
vendor: ibm
product: aspera_shares
affected:
  - 'aspera_shares >= 1.9.9, < 1.11.1'
patched:
  - aspera_shares 1.11.1
published: '2026-04-01'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66485'
references:
  - url: 'https://www.ibm.com/support/pages/node/7267848'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.002
epssPercentile: 0.0883
ingestedAt: '2026-09-30T22:27:27.745Z'
---

## Overview

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

## Affected

- `aspera_shares >= 1.9.9, < 1.11.1`

## Remediation

Upgrade past the affected range:

- `aspera_shares 1.11.1`
