« Back to list

CVE-2026-56813

Status: DeferredLow (2.1)—

Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes.

The Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set-Cookie response header by interpolating the cookie value and its path, domain, same_site, and extra attributes directly into the header without neutralizing the ; delimiter that separates cookie attributes.

An application that places attacker-controlled data into a cookie value or attribute (for example via Plug.Conn.put_resp_cookie/4 when reflecting a username or preference) lets an attacker inject a ; to append or override cookie attributes (such as Domain and Path scope, or dropping the Secure and HttpOnly flags), enabling cookie tossing and session fixation.

Read full descriptionShow less

Carriage return, line feed, and null bytes are rejected by Plug.Conn header validation, so HTTP response splitting is not possible, but attribute injection through ; is not prevented.

This issue affects plug: from 0.1.0 before 1.16.6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.19.1 before 1.19.5, and from 1.20.0 before 1.20.3.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-56813",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-56813",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-10T14:43:36.298825Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 2.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "LOW",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:elixir-plug:plug:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/elixir-plug/plug",
          "vendor": "elixir-plug",
          "modules": [
            "'Elixir.Plug.Conn.Cookies'",
            "'Elixir.Plug.Conn'"
          ],
          "product": "plug",
          "versions": [
            {
              "status": "affected",
              "version": "0.1.0",
              "lessThan": "1.16.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.17.0",
              "lessThan": "1.17.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.18.0",
              "lessThan": "1.18.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.19.1",
              "lessThan": "1.19.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.20.0",
              "lessThan": "1.20.3",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:hex/plug",
          "packageName": "plug",
          "programFiles": [
            "lib/plug/conn/cookies.ex"
          ],
          "collectionURL": "https://repo.hex.pm",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "'Elixir.Plug.Conn.Cookies':encode/2"
            },
            {
              "name": "'Elixir.Plug.Conn':put_resp_cookie/4"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:elixir-plug:plug:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/elixir-plug/plug",
          "vendor": "elixir-plug",
          "modules": [
            "'Elixir.Plug.Conn.Cookies'",
            "'Elixir.Plug.Conn'"
          ],
          "product": "plug",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "3f00dfad4e20ba88472e315c90a25742bf178f8e",
                  "status": "unaffected"
                },
                {
                  "at": "a6d1248659022749869963fd302687165ecf8c8b",
                  "status": "unaffected"
                },
                {
                  "at": "4167981747fe9ce75f374b94a28861ae950ea992",
                  "status": "unaffected"
                },
                {
                  "at": "149d9ed68fee0b4f77efd1e835ce5d785856697b",
                  "status": "unaffected"
                },
                {
                  "at": "eceb8315ce9a31ef784943a95a8624ebd1bc7e06",
                  "status": "unaffected"
                }
              ],
              "version": "f26876aa67aaeb38e616638aa3efbcc2fe2906a5",
              "lessThan": "*",
              "versionType": "git"
            }
          ],
          "packageURL": "pkg:github/elixir-plug/plug",
          "packageName": "elixir-plug/plug",
          "programFiles": [
            "lib/plug/conn/cookies.ex"
          ],
          "collectionURL": "https://github.com",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "'Elixir.Plug.Conn.Cookies':encode/2"
            },
            {
              "name": "'Elixir.Plug.Conn':put_resp_cookie/4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-07-10T13:16:20.663",
  "references": [
    {
      "url": "https://cna.erlef.org/cves/CVE-2026-56813.html",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-plug/plug/commit/149d9ed68fee0b4f77efd1e835ce5d785856697b",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-plug/plug/commit/3f00dfad4e20ba88472e315c90a25742bf178f8e",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-plug/plug/commit/4167981747fe9ce75f374b94a28861ae950ea992",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-plug/plug/commit/a6d1248659022749869963fd302687165ecf8c8b",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-plug/plug/commit/eceb8315ce9a31ef784943a95a8624ebd1bc7e06",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-plug/plug/commit/f26876aa67aaeb38e616638aa3efbcc2fe2906a5",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-plug/plug/security/advisories/GHSA-wpmj-jh88-rpgm",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://osv.dev/vulnerability/EEF-CVE-2026-56813",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "description": [
        {
          "lang": "en",
          "value": "CWE-141"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes.\n\nThe Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set-Cookie response header by interpolating the cookie value and its path, domain, same_site, and extra attributes directly into the header without neutralizing the ; delimiter that separates cookie attributes.\n\nAn application that places attacker-controlled data into a cookie value or attribute (for example via Plug.Conn.put_resp_cookie/4 when reflecting a username or preference) lets an attacker inject a ; to append or override cookie attributes (such as Domain and Path scope, or dropping the Secure and HttpOnly flags), enabling cookie tossing and session fixation. Carriage return, line feed, and null bytes are rejected by Plug.Conn header validation, so HTTP response splitting is not possible, but attribute injection through ; is not prevented.\n\nThis issue affects plug: from 0.1.0 before 1.16.6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.19.1 before 1.19.5, and from 1.20.0 before 1.20.3."
    }
  ],
  "lastModified": "2026-09-24T22:17:00.960",
  "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}