CVE-2026-49756 PUBLISHED

Multipart form-data header injection in Req via unescaped name/filename/content_type

Assigner: EEF
Reserved: 01.06.2026 Published: 08.06.2026 Updated: 08.06.2026

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata.

Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part headers by interpolating the caller-supplied name, filename, and content_type values directly into the content-disposition and content-type lines with no escaping or CRLF stripping. A value containing ", \r, or \n closes the surrounding quoted value and starts a new header line; an additional \r\n--<boundary> terminates the current part and prepends a smuggled part of the attacker's choosing.

This is reachable through every supported way of supplying a part. It is particularly easy when value is a %File.Stream{}, because filename then defaults to Path.basename(stream.path) and POSIX filenames may legitimately contain \r and \n. Any application that forwards user-controlled filenames (or field names / MIME types) through Req.post/2 with form_multipart: lets an attacker inject arbitrary headers into the outgoing multipart body or smuggle additional fields and parts into the request the victim service sends downstream.

This issue affects req: from 0.5.3 before 0.6.0.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 2.1

Product Status

Vendor wojtekmach
Product req
Versions Default: unaffected
  • affected from 0.5.3 to 0.6.0 (excl.)
Vendor wojtekmach
Product req
Versions Default: unaffected
  • affected from 60253dbe9436cb8e9c738f895032f2e87939b597 to 74506ff2c5addf74df85d79dc726e9b2e264a8ba (excl.)

Workarounds

Sanitize attacker-influenced name, filename, and content_type values before passing them to Req.post/2 with form_multipart:. At minimum, reject (or strip) any value containing \r, \n, or ". When forwarding uploads, derive filename from a normalised string rather than Path.basename/1 on a user-controlled path.

Credits

  • Peter Ullrich finder
  • Wojtek Mach remediation developer
  • Jonatan Männchen / EEF analyst

References

Problem Types

  • CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') CWE

Impacts

  • CAPEC-33 HTTP Request Smuggling
  • CAPEC-105 HTTP Request Splitting