CVE-2020-24275: A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL. Fix is in 4.5.3: https://github.com/swoole/swoole-src/commit/4bab1a2403adcbf97104ea81a521987f77d32790 This appears to be XSS more than "arbitrary code execution".