What is CVE-2026-71572?
A response header injection vulnerability has been identified in Joomla! Core download views due to lack of output processing, affecting versions 3.0.0-5.4.7 and 6.0.0-6.1.2. This flaw could lead to reflected file download or content-type confusion attacks. Affected users should immediately apply the security update.
Azərbaycanca: Joomla! CMS-in müxtəlif versiyalarında "download views" komponentində çıxışın düzgün işlənməməsi səbəbindən cavab başlığı inyeksiyası (response header injection) zəifliyi aşkar edilib. Bu, reflected file download və content-type confusion kimi hücumlara yol aça bilər. Joomla 3.0.0-5.4.7 və 6.0.0-6.1.2 versiyalarını istifadə edən təşkilatlar dərhal təhlükəsizlik yeniləməsini tətbiq etməlidir.
FAQ2
In which Joomla! component is the CVE-2026-71572 vulnerability found, and what attacks could it lead to?
The vulnerability is a response header injection found in Joomla! Core download views due to a lack of output processing. This flaw could lead to reflected file download or content-type confusion attacks.
Which Joomla! versions are affected by CVE-2026-71572?
The vulnerability affects Joomla! versions ranging from 3.0.0 through 5.4.7, and from 6.0.0 through 6.1.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.