VYPR
Low severity3.7NVD Advisory· Published Jun 2, 2026· Updated Aug 19, 2026

CVE-2026-48596

CVE-2026-48596

Description

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2.

Tesla.Multipart.add_content_type_param/2 appends caller-supplied strings to the multipart content_type_params list without validating for CR (\r) or LF (\n) characters. Tesla.Multipart.headers/1 then joins these params verbatim with "; " to construct the outgoing Content-Type header value. A param containing \r\n splits the header line, allowing arbitrary headers to be injected into the outbound HTTP request. Any application that forwards untrusted input (such as a user-supplied charset or parameter string) into add_content_type_param/2 is affected.

This issue affects tesla: from 0.8.0 before 1.18.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
teslaHex
>= 0.8.0, < 1.18.31.18.3

Affected products

2
  • cpe:2.3:a:elixir-tesla:tesla:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:elixir-tesla:tesla:*:*:*:*:*:*:*:*range: >=0.8.0,<1.18.3
    • (no CPE)range: >=0.8.0 <1.18.3

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.