---
id: CVE-2026-39915
title: >-
  TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows
  remote attackers to inject arbitrary HTTP headers and response body content by
  embedding unsanitized carriage return and line feed sequences in the rt URL
  paramet…
summary: >-
  TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows
  remote attackers to inject arbitrary HTTP headers and response body content by
  embedding unsanitized carriage return and line feed sequences in the rt URL
  paramet…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-113
published: '2026-08-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:43:32.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39915'
references:
  - url: >-
      https://tim-doc.atlassian.net/wiki/spaces/eng/pages/230981636/Release+Notes
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tim-flow-crlf-injection-via-rt-parameter
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00476
epssPercentile: 0.38535
ingestedAt: '2026-09-24T20:51:40.222Z'
---

## Overview

TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized carriage return and line feed sequences in the rt URL parameter, which is reflected into Set-Cookie response headers. Attackers can craft malicious requests to induce authenticated users to execute arbitrary JavaScript in their browser context, enabling session token theft and account credential modification.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
