H2O 1.6.2 released fixing a response splitting vulnerability in redirect handler I have just released H2O version 1.6.2 that includes a fix for a response splitting vulnerability found in prior releases. Users using the redirect directive are affected; they are advised to update immediately. Edit: version 1.7.0-beta3 has also been released fixing the same issue in the earlier releases of 1.7.0 bet