CVE-2026-48596

Severity CVSS v4.0:
LOW
Type:
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
Publication date:
02/06/2026
Last modified:
03/06/2026

Description

Improper Neutralization of CRLF Sequences in HTTP Headers (&amp;#39;HTTP Request/Response Splitting&amp;#39;) vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2.<br /> <br /> Tesla.Multipart.add_content_type_param/2 appends caller-supplied strings to the multipart content_type_params list without validating for CR (\r) or LF (\n) characters. Tesla.Multipart.headers/1 then joins these params verbatim with "; " to construct the outgoing Content-Type header value. A param containing \r\n splits the header line, allowing arbitrary headers to be injected into the outbound HTTP request. Any application that forwards untrusted input (such as a user-supplied charset or parameter string) into add_content_type_param/2 is affected.<br /> <br /> This issue affects tesla: from 0.8.0 before 1.18.3.