{"id":"CVE-2026-48596","aliases":["GHSA-q7jx-v53g-848w"],"title":"Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`","summary":"Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`","severity":"low","cwe":["CWE-93","CWE-113"],"vendor":"tesla","product":"tesla","ecosystem":"erlang","affected":["tesla >= 0.8.0, < 1.18.3"],"patched":["tesla 1.18.3"],"published":"2026-07-10","updated":"2026-07-10","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-q7jx-v53g-848w","references":[{"url":"https://github.com/elixir-tesla/tesla/security/advisories/GHSA-q7jx-v53g-848w"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48596"},{"url":"https://github.com/elixir-tesla/tesla/commit/23601edac5d22ba9407b427967b5bdbda201aec2"},{"url":"https://cna.erlef.org/cves/CVE-2026-48596.html"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-48596"},{"url":"https://github.com/advisories/GHSA-q7jx-v53g-848w"}],"tags":["ghsa","erlang"],"epss":0.00239,"epssPercentile":0.15245,"ingestedAt":"2026-07-10T00:54:12.246Z","slug":"CVE-2026-48596","body":"## Overview\n\n### Summary\n\n`Tesla.Multipart.add_content_type_param/2` appends caller-supplied strings to the multipart `Content-Type` header with no validation. A param value containing `\\r\\n` splits the header line, allowing an attacker who controls any content-type parameter (charset, boundary parameter, etc.) to inject arbitrary headers into the outbound HTTP request.\n\n### Details\n\n`add_content_type_param/2` in `lib/tesla/multipart.ex` stores the supplied string directly in `multipart.content_type_params` without any CR/LF check. `headers/1` then joins all params with `\"; \"` and appends the result verbatim to the `Content-Type` header value. Because HTTP headers are delimited by `\\r\\n`, a param containing that sequence breaks out of the header field and introduces new header lines before the adapter writes the request to the socket.\n\nThe precondition is that untrusted input reaches `add_content_type_param/2`, which is the normal pattern for applications that accept user-supplied charset values, file type parameters, or any other content-type extension fields.\n\n### PoC\n\n1. Call `Tesla.Multipart.add_content_type_param/2` with a value containing `\\r\\nX-Injected: pwned`.\n2. Pass the resulting `Multipart` struct as the request body via any Tesla adapter.\n3. The raw request on the wire contains `X-Injected: pwned` as a standalone header line.\n\n### Impact\n\nLow severity (CVSS v4.0: 2.1). Any application using `tesla` 0.8.0 through 1.18.2 that passes untrusted input into `Tesla.Multipart.add_content_type_param/2` is affected. Consequences range from forging arbitrary outbound request headers to potential request smuggling against the upstream server. Fixed in tesla 1.18.3.\n\n### Workarounds\n\nValidate content-type parameter strings before passing them to `Tesla.Multipart.add_content_type_param/2`, rejecting any value that contains `\\r` or `\\n`.\n\n### Reesources\n\n* Introduction commit: https://github.com/elixir-tesla/tesla/commit/6ebfdb9abe9c6f119408045b933d82462decd351\n* Patch commit: https://github.com/elixir-tesla/tesla/commit/23601edac5d22ba9407b427967b5bdbda201aec2\n\n## Affected packages\n\n- `tesla >= 0.8.0, < 1.18.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `tesla 1.18.3`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}