PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.
https://gist.github.com/Hurdano/8244855ef8ec364fd98a2693de6e30c5