<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T07:22:39.939564+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-375454</id>
    <title>EUVD-2026-375454</title>
    <updated>2026-10-05T07:22:39.987197+00:00</updated>
    <content>EUVD-2026-375454</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-375454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48596</id>
    <title>fkie_cve-2026-48596</title>
    <updated>2026-10-05T07:22:39.987279+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2.</p>
<p>Tesla.Multipart.add_content_type_param/2 appends caller-supplied strings to the multipart content_type_params list without validating for CR (\r) or LF (\n) characters. Tesla.Multipart.headers/1 then joins these params verbatim with "; " to construct the outgoing Content-Type header value. A param containing \r\n splits the header line, allowing arbitrary headers to be injected into the outbound HTTP request. Any application that forwards untrusted input (such as a user-supplied charset or parameter string) into add_content_type_param/2 is affected.</p>
<p>This issue affects tesla: from 0.8.0 before 1.18.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48596"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q7jx-v53g-848w</id>
    <title>GHSA-q7jx-v53g-848w — Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`</title>
    <updated>2026-10-05T07:22:39.987322+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Hex: tesla</p>
<p>### Summary</p>
<p>`Tesla.Multipart.add_content_type_param/2` appends caller-supplied strings to the multipart `Content-Type` header with no validation. A param value containing `\r\n` splits the header line, allowing an attacker who controls any content-type parameter (charset, boundary parameter, etc.) to inject arbitrary headers into the outbound HTTP request.</p>
<p>### Details</p>
<p>`add_content_type_param/2` in `lib/tesla/multipart.ex` stores the supplied string directly in `multipart.content_type_params` without any CR/LF check. `headers/1` then joins all params with `"; "` and appends the result verbatim to the `Content-Type` header value. Because HTTP headers are delimited by `\r\n`, a param containing that sequence breaks out of the header field and introduces new header lines before the adapter writes the request to the socket.</p>
<p>The precondition is that untrusted input reaches `add_content_type_param/2`, which is the normal pattern for applications that accept user-supplied charset values, file type parameters, or any other content-type extension fields.</p>
<p>### PoC</p>
<p>1. Call `Tesla.Multipart.add_content_type_param/2` with a value containing `\r\nX-Injected: pwned`.
2. Pass the resulting `Multipart` struct as the request body via any Tesla adapter.
3. The raw request on the wire contains `X-Injected: pwned` as a standalone header line.</p>
<p>### Impact</p>
<p>Low severity (CVSS v4.0: 2.1). Any application using `tesla` 0.8.0 through 1.18.2 that passes untrusted input into `Tesla.Multipart.add_co…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q7jx-v53g-848w"/>
  </entry>
</feed>
