CVE-2026-49756
Multipart form-data header injection in Req via unescaped name/filename/content_type
Description
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata. Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part headers by interpolating the caller-supplied name, filename, and content_type values directly into the content-disposition and content-type lines with no escaping or CRLF stripping. A value containing ", \r, or \n closes the surrounding quoted value and starts a new header line; an additional \r\n--<boundary> terminates the current part and prepends a smuggled part of the attacker's choosing. This is reachable through every supported way of supplying a part. It is particularly easy when value is a %File.Stream{}, because filename then defaults to Path.basename(stream.path) and POSIX filenames may legitimately contain \r and \n. Any application that forwards user-controlled filenames (or field names / MIME types) through Req.post/2 with form_multipart: lets an attacker inject arbitrary headers into the outgoing multipart body or smuggle additional fields and parts into the request the victim service sends downstream. This issue affects req: from 0.5.3 before 0.6.0.
INFO
Published Date :
June 8, 2026, 4:16 p.m.
Last Modified :
Aug. 18, 2026, 7:15 p.m.
Remotely Exploit :
Yes !
Source :
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | LOW | [email protected] | ||||
| CVSS 4.0 | LOW | 6b3ad84c-e1a6-4bf7-a703-f496b71e49db | ||||
| CVSS 4.0 | LOW | 6b3ad84c-e1a6-4bf7-a703-f496b71e49db |
Solution
- Update Req to version 0.6.0 or later.
- Validate and sanitize all user-supplied input.
- Avoid directly interpolating user input into headers.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-49756.
| URL | Resource |
|---|---|
| https://cna.erlef.org/cves/CVE-2026-49756.html | Third Party Advisory Mitigation |
| https://github.com/wojtekmach/req/commit/74506ff2c5addf74df85d79dc726e9b2e264a8ba | Patch |
| https://github.com/wojtekmach/req/security/advisories/GHSA-px9f-whj3-246m | Vendor Advisory |
| https://osv.dev/vulnerability/EEF-CVE-2026-49756 | Third Party Advisory |
| https://github.com/wojtekmach/req/security/advisories/GHSA-px9f-whj3-246m | Vendor Advisory |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-49756 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-49756
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-49756 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-49756 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Aug. 18, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Added CPE Configuration OR *cpe:2.3:a:wojtekmach:req:*:*:*:*:*:*:*:* versions from (including) 0.5.3 up to (excluding) 0.6.0 Added Reference Type CISA-ADP: https://github.com/wojtekmach/req/security/advisories/GHSA-px9f-whj3-246m Types: Vendor Advisory Added Reference Type EEF: https://cna.erlef.org/cves/CVE-2026-49756.html Types: Mitigation, Third Party Advisory Added Reference Type EEF: https://github.com/wojtekmach/req/commit/74506ff2c5addf74df85d79dc726e9b2e264a8ba Types: Patch Added Reference Type EEF: https://github.com/wojtekmach/req/security/advisories/GHSA-px9f-whj3-246m Types: Vendor Advisory Added Reference Type EEF: https://osv.dev/vulnerability/EEF-CVE-2026-49756 Types: Third Party Advisory -
CVE Translated by [email protected]
Jul. 23, 2026
Action Type Old Value New Value Added Translation Title: Req de wojtekmach, Description: La vulnerabilidad de Neutralización Incorrecta de Secuencias CRLF ('Inyección CRLF') en wojtekmach Req permite el contrabando de parámetros multipart a través de metadatos de parte influenciados por el atacante. Req.Utils.encode_form_part/2 en lib/req/utils.ex construye los encabezados por parte interpolando los valores de nombre, nombre de archivo y tipo de contenido suministrados por el llamador directamente en las líneas de content-disposition y content-type sin escape ni eliminación de CRLF. Un valor que contiene ", \r, o \n cierra el valor entre comillas circundante y comienza una nueva línea de encabezado; un \r\n--<boundary> adicional termina la parte actual y antepone una parte contrabandeada a elección del atacante. Esto es alcanzable a través de cada forma compatible de suministrar una parte. Es particularmente fácil cuando el valor es un %File.Stream{}, porque el nombre de archivo por defecto es Path.basename(stream.path) y los nombres de archivo POSIX pueden contener legítimamente \r y \n. Cualquier aplicación que reenvíe nombres de archivo controlados por el usuario (o nombres de campo / tipos MIME) a través de Req.post/2 con form_multipart: permite a un atacante inyectar encabezados arbitrarios en el cuerpo multipart saliente o contrabandear campos y partes adicionales en la solicitud que el servicio víctima envía aguas abajo. Este problema afecta a req: desde 0.5.3 antes de 0.6.0. -
CVE Modified by 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'cpes': ['cpe:2.3:a:wojtekmach:req:*:*:*:*:*:*:*:*'], 'repo': 'https://github.com/wojtekmach/req', 'vendor': 'wojtekmach', 'modules': ["'Elixir.Req.Utils'"], 'product': 'req', 'versions': [{'status': 'affected', 'version': '0.5.3', 'lessThan': '0.6.0', 'versionType': 'semver'}], 'packageURL': 'pkg:hex/req', 'packageName': 'req', 'programFiles': ['lib/req/utils.ex'], 'collectionURL': 'https://repo.hex.pm', 'defaultStatus': 'unaffected', 'programRoutines': [{'name': "'Elixir.Req.Utils':encode_form_part/2"}]}, {'cpes': ['cpe:2.3:a:wojtekmach:req:*:*:*:*:*:*:*:*'], 'repo': 'https://github.com/wojtekmach/req.git', 'vendor': 'wojtekmach', 'modules': ["'Elixir.Req.Utils'"], 'product': 'req', 'versions': [{'status': 'affected', 'version': '60253dbe9436cb8e9c738f895032f2e87939b597', 'lessThan': '74506ff2c5addf74df85d79dc726e9b2e264a8ba', 'versionType': 'git'}], 'packageURL': 'pkg:github/wojtekmach/req', 'packageName': 'wojtekmach/req', 'programFiles': ['lib/req/utils.ex'], 'collectionURL': 'https://github.com', 'defaultStatus': 'unaffected', 'programRoutines': [{'name': "'Elixir.Req.Utils':encode_form_part/2"}]}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-49756', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'poc'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-06-08T16:05:54.070488Z'} -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 08, 2026
Action Type Old Value New Value Added Reference https://github.com/wojtekmach/req/security/advisories/GHSA-px9f-whj3-246m -
New CVE Received by 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Jun. 08, 2026
Action Type Old Value New Value Added Description Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata. Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part headers by interpolating the caller-supplied name, filename, and content_type values directly into the content-disposition and content-type lines with no escaping or CRLF stripping. A value containing ", \r, or \n closes the surrounding quoted value and starts a new header line; an additional \r\n--<boundary> terminates the current part and prepends a smuggled part of the attacker's choosing. This is reachable through every supported way of supplying a part. It is particularly easy when value is a %File.Stream{}, because filename then defaults to Path.basename(stream.path) and POSIX filenames may legitimately contain \r and \n. Any application that forwards user-controlled filenames (or field names / MIME types) through Req.post/2 with form_multipart: lets an attacker inject arbitrary headers into the outgoing multipart body or smuggle additional fields and parts into the request the victim service sends downstream. This issue affects req: from 0.5.3 before 0.6.0. Added CVSS V4.0 AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Added CWE CWE-93 Added Reference https://cna.erlef.org/cves/CVE-2026-49756.html Added Reference https://github.com/wojtekmach/req/commit/74506ff2c5addf74df85d79dc726e9b2e264a8ba Added Reference https://github.com/wojtekmach/req/security/advisories/GHSA-px9f-whj3-246m Added Reference https://osv.dev/vulnerability/EEF-CVE-2026-49756