---
id: CVE-2026-4096
title: >-
  IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection,
  caused by improper validation of input by the HOST headers
summary: >-
  IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection,
  caused by improper validation of input by the HOST headers. This could allow
  an attacker to conduct various attacks against the vulnerable system,
  including cros…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-644
vendor: hcltech
product: devops_plan
affected:
  - 'devops_plan >= 3.0.0, < 3.0.7'
patched:
  - devops_plan 3.0.7
published: '2026-06-11'
updated: '2026-07-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4096'
references:
  - url: 'https://www.ibm.com/support/pages/node/7275005'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00149
epssPercentile: 0.04448
ingestedAt: '2026-07-28T13:36:10.094Z'
---

## Overview

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking

## Affected

- `devops_plan >= 3.0.0, < 3.0.7`

## Remediation

Upgrade past the affected range:

- `devops_plan 3.0.7`
