216.73.216.197

CVE-2026-44214

· Published 26/05/2026 20:16 · Modified 27/05/2026 14:16

Labels: CVE-2026-44214 2026-05-26CVE-2026-44214CWE-93[email protected]

Essential information

Published
26/05/2026 20:16
Modified
27/05/2026 14:16
Author
Creator
CVSS
5.8 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

CVSS metrics

Description

eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage before serializing them. An attacker who controls either field can inject arbitrary Server-Sent Events line terminators (\n, \r, or \r\n) and thereby forge additional SSE fields or entire messages on the stream. This vulnerability is fixed in 1.0.2.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
eventsource-encoder / eventsource-encoder cpe:2.3:a:eventsource-encoder:eventsource-encoder:1.0.2:*:*:*:*:*:*:*
eventsource-encoder / eventsource-encoder cpe:2.3:a:eventsource-encoder:eventsource-encoder:*:*:*:*:*:*:*:*

References