CVE-2026-54163
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
17/07/2026
Last modified:
23/07/2026
Description
secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and build_report_to_directive interpolate caller-supplied strings without scrubbing ;, \r, or \n. When untrusted input reaches SecureHeaders.override_content_security_policy_directives or append APIs for :sandbox, :plugin_types, or :report_to, an attacker can inject a CSP directive such as script-src 'unsafe-inline' * before the legitimate script-src, enabling XSS reachability through these sinks or CSP report exfiltration. This issue is fixed in version 7.3.0.
Impact
Base Score 3.x
4.70
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/github/secure_headers/commit/286a79dea80c6a9be4ca93e0f284c923cf77e539
- https://github.com/github/secure_headers/releases/tag/v7.3.0
- https://github.com/github/secure_headers/security/advisories/GHSA-rqq5-2gf9-4w4q
- https://github.com/github/secure_headers/security/advisories/GHSA-rqq5-2gf9-4w4q



