Tesla
Elixir-Tesla · 5 CVEs
CVE-2026-48596
LOW
CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection
Jun 2, 2026
CVE-2026-48594
HIGH
Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
Jun 2, 2026
CVE-2026-48595
HIGH
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
Jun 2, 2026
CVE-2026-48597
HIGH
Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint
Jun 2, 2026
CVE-2026-48598
LOW
CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection
Jun 2, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-48596 | CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection | LOW | 0.35% | Jun 2, 2026 |
| CVE-2026-48594 | Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression | HIGH | 0.70% | Jun 2, 2026 |
| CVE-2026-48595 | Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects | HIGH | 0.67% | Jun 2, 2026 |
| CVE-2026-48597 | Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint | HIGH | 0.63% | Jun 2, 2026 |
| CVE-2026-48598 | CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection | LOW | 0.34% | Jun 2, 2026 |
Showing 1 to 5 of 5 CVEs