CVE-2026-56813
Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes.
The Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set-Cookie response header by interpolating the cookie value and its path, domain, same_site, and extra attributes directly into the header without neutralizing the ; delimiter that separates cookie attributes.
An application that places attacker-controlled data into a cookie value or attribute (for example via Plug.Conn.put_resp_cookie/4 when reflecting a username or preference) lets an attacker inject a ; to append or override cookie attributes (such as Domain and Path scope, or dropping the Secure and HttpOnly flags), enabling cookie tossing and session fixation.
Leer descripción completaMostrar menos
Carriage return, line feed, and null bytes are rejected by Plug.Conn header validation, so HTTP response splitting is not possible, but attribute injection through ; is not prevented.
This issue affects plug: from 0.1.0 before 1.16.6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.19.1 before 1.19.5, and from 1.20.0 before 1.20.3.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-141
Referencias
- https://cna.erlef.org/cves/CVE-2026-56813.html
- https://github.com/elixir-plug/plug/commit/149d9ed68fee0b4f77efd1e835ce5d785856697b
- https://github.com/elixir-plug/plug/commit/3f00dfad4e20ba88472e315c90a25742bf178f8e
- https://github.com/elixir-plug/plug/commit/4167981747fe9ce75f374b94a28861ae950ea992
- https://github.com/elixir-plug/plug/commit/a6d1248659022749869963fd302687165ecf8c8b
- https://github.com/elixir-plug/plug/commit/eceb8315ce9a31ef784943a95a8624ebd1bc7e06
- https://github.com/elixir-plug/plug/commit/f26876aa67aaeb38e616638aa3efbcc2fe2906a5
- https://github.com/elixir-plug/plug/security/advisories/GHSA-wpmj-jh88-rpgm
- https://osv.dev/vulnerability/EEF-CVE-2026-56813
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-56813",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-56813",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-07-10T14:43:36.298825Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 2.1,
"Automatable": "NOT_DEFINED",
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:elixir-plug:plug:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/elixir-plug/plug",
"vendor": "elixir-plug",
"modules": [
"'Elixir.Plug.Conn.Cookies'",
"'Elixir.Plug.Conn'"
],
"product": "plug",
"versions": [
{
"status": "affected",
"version": "0.1.0",
"lessThan": "1.16.6",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.17.0",
"lessThan": "1.17.4",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.18.0",
"lessThan": "1.18.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.19.1",
"lessThan": "1.19.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.20.0",
"lessThan": "1.20.3",
"versionType": "semver"
}
],
"packageURL": "pkg:hex/plug",
"packageName": "plug",
"programFiles": [
"lib/plug/conn/cookies.ex"
],
"collectionURL": "https://repo.hex.pm",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.Plug.Conn.Cookies':encode/2"
},
{
"name": "'Elixir.Plug.Conn':put_resp_cookie/4"
}
]
},
{
"cpes": [
"cpe:2.3:a:elixir-plug:plug:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/elixir-plug/plug",
"vendor": "elixir-plug",
"modules": [
"'Elixir.Plug.Conn.Cookies'",
"'Elixir.Plug.Conn'"
],
"product": "plug",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "3f00dfad4e20ba88472e315c90a25742bf178f8e",
"status": "unaffected"
},
{
"at": "a6d1248659022749869963fd302687165ecf8c8b",
"status": "unaffected"
},
{
"at": "4167981747fe9ce75f374b94a28861ae950ea992",
"status": "unaffected"
},
{
"at": "149d9ed68fee0b4f77efd1e835ce5d785856697b",
"status": "unaffected"
},
{
"at": "eceb8315ce9a31ef784943a95a8624ebd1bc7e06",
"status": "unaffected"
}
],
"version": "f26876aa67aaeb38e616638aa3efbcc2fe2906a5",
"lessThan": "*",
"versionType": "git"
}
],
"packageURL": "pkg:github/elixir-plug/plug",
"packageName": "elixir-plug/plug",
"programFiles": [
"lib/plug/conn/cookies.ex"
],
"collectionURL": "https://github.com",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.Plug.Conn.Cookies':encode/2"
},
{
"name": "'Elixir.Plug.Conn':put_resp_cookie/4"
}
]
}
]
}
],
"published": "2026-07-10T13:16:20.663",
"references": [
{
"url": "https://cna.erlef.org/cves/CVE-2026-56813.html",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/149d9ed68fee0b4f77efd1e835ce5d785856697b",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/3f00dfad4e20ba88472e315c90a25742bf178f8e",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/4167981747fe9ce75f374b94a28861ae950ea992",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/a6d1248659022749869963fd302687165ecf8c8b",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/eceb8315ce9a31ef784943a95a8624ebd1bc7e06",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/f26876aa67aaeb38e616638aa3efbcc2fe2906a5",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/security/advisories/GHSA-wpmj-jh88-rpgm",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-56813",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"description": [
{
"lang": "en",
"value": "CWE-141"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes.\n\nThe Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set-Cookie response header by interpolating the cookie value and its path, domain, same_site, and extra attributes directly into the header without neutralizing the ; delimiter that separates cookie attributes.\n\nAn application that places attacker-controlled data into a cookie value or attribute (for example via Plug.Conn.put_resp_cookie/4 when reflecting a username or preference) lets an attacker inject a ; to append or override cookie attributes (such as Domain and Path scope, or dropping the Secure and HttpOnly flags), enabling cookie tossing and session fixation. Carriage return, line feed, and null bytes are rejected by Plug.Conn header validation, so HTTP response splitting is not possible, but attribute injection through ; is not prevented.\n\nThis issue affects plug: from 0.1.0 before 1.16.6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.19.1 before 1.19.5, and from 1.20.0 before 1.20.3."
}
],
"lastModified": "2026-09-24T22:17:00.960",
"sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}