# CVE-2026-48596

## Summary

- **CVE ID:** CVE-2026-48596
- **Severity:** LOW
- **CVSS Score:** 2.1 (CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N)
- **CWE:** CWE-113
- **Published:** Jun 2, 2026
- **Last Modified:** Jun 4, 2026

## Description

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2.

Tesla.Multipart.add_content_type_param/2 appends caller-supplied strings to the multipart content_type_params list without validating for CR (\r) or LF (\n) characters. Tesla.Multipart.headers/1 then joins these params verbatim with "; " to construct the outgoing Content-Type header value. A param containing \r\n splits the header line, allowing arbitrary headers to be injected into the outbound HTTP request. Any application that forwards untrusted input (such as a user-supplied charset or parameter string) into add_content_type_param/2 is affected.

This issue affects tesla: from 0.8.0 before 1.18.3.

## Affected Products

- elixir-tesla — tesla (0.8.0)
- elixir-tesla — tesla (6ebfdb9abe9c6f119408045b933d82462decd351)

## References

- [CNA](https://github.com/elixir-tesla/tesla/security/advisories/GHSA-q7jx-v53g-848w)
- [CNA](https://cna.erlef.org/cves/CVE-2026-48596.html)
- [CNA](https://osv.dev/vulnerability/EEF-CVE-2026-48596)
- [CNA](https://github.com/elixir-tesla/tesla/commit/23601edac5d22ba9407b427967b5bdbda201aec2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.24%
- **EPSS Percentile:** 14.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._