Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q7jx-v53g-848w

Опубликовано: 10 июл. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.1

Описание

Tesla has CRLF injection in request Content-Type header via add_content_type_param

Summary

Tesla.Multipart.add_content_type_param/2 appends caller-supplied strings to the multipart Content-Type header with no validation. A param value containing \r\n splits the header line, allowing an attacker who controls any content-type parameter (charset, boundary parameter, etc.) to inject arbitrary headers into the outbound HTTP request.

Details

add_content_type_param/2 in lib/tesla/multipart.ex stores the supplied string directly in multipart.content_type_params without any CR/LF check. headers/1 then joins all params with "; " and appends the result verbatim to the Content-Type header value. Because HTTP headers are delimited by \r\n, a param containing that sequence breaks out of the header field and introduces new header lines before the adapter writes the request to the socket.

The precondition is that untrusted input reaches add_content_type_param/2, which is the normal pattern for applications that accept user-supplied charset values, file type parameters, or any other content-type extension fields.

PoC

  1. Call Tesla.Multipart.add_content_type_param/2 with a value containing \r\nX-Injected: pwned.
  2. Pass the resulting Multipart struct as the request body via any Tesla adapter.
  3. The raw request on the wire contains X-Injected: pwned as a standalone header line.

Impact

Low severity (CVSS v4.0: 2.1). Any application using tesla 0.8.0 through 1.18.2 that passes untrusted input into Tesla.Multipart.add_content_type_param/2 is affected. Consequences range from forging arbitrary outbound request headers to potential request smuggling against the upstream server. Fixed in tesla 1.18.3.

Workarounds

Validate content-type parameter strings before passing them to Tesla.Multipart.add_content_type_param/2, rejecting any value that contains \r or \n.

Reesources

Пакеты

Наименование

tesla

Hex
Затронутые версииВерсия исправления

>= 0.8.0, < 1.18.3

1.18.3

EPSS

Процентиль: 7%
0.00171
Низкий

2.1 Low

CVSS4

Дефекты

CWE-113
CWE-93

Связанные уязвимости

nvd
2 месяца назад

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2. Tesla.Multipart.add_content_type_param/2 appends caller-supplied strings to the multipart content_type_params list without validating for CR (\r) or LF (\n) characters. Tesla.Multipart.headers/1 then joins these params verbatim with "; " to construct the outgoing Content-Type header value. A param containing \r\n splits the header line, allowing arbitrary headers to be injected into the outbound HTTP request. Any application that forwards untrusted input (such as a user-supplied charset or parameter string) into add_content_type_param/2 is affected. This issue affects tesla: from 0.8.0 before 1.18.3.

debian
2 месяца назад

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Reque ...

EPSS

Процентиль: 7%
0.00171
Низкий

2.1 Low

CVSS4

Дефекты

CWE-113
CWE-93