CVE-2026-56813
Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes.
The Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set-Cookie response header by interpolating the cookie value and its path, domain, same_site, and extra attributes directly into the header without neutralizing the ; delimiter that separates cookie attributes.
An application that places attacker-controlled data into a cookie value or attribute (for example via Plug.Conn.put_resp_cookie/4 when reflecting a username or preference) lets an attacker inject a ; to append or override cookie attributes (such as Domain and Path scope, or dropping the Secure and HttpOnly flags), enabling cookie tossing and session fixation.
Read full descriptionShow less
Carriage return, line feed, and null bytes are rejected by Plug.Conn header validation, so HTTP response splitting is not possible, but attribute injection through ; is not prevented.
This issue affects plug: from 0.1.0 before 1.16.6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.19.1 before 1.19.5, and from 1.20.0 before 1.20.3.
CVSS
- Version: 4.0
- Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Base score: 2.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.22%
- Percentile among all scored CVEs: 11
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-141
References
- https://cna.erlef.org/cves/CVE-2026-56813.html
- https://github.com/elixir-plug/plug/commit/149d9ed68fee0b4f77efd1e835ce5d785856697b
- https://github.com/elixir-plug/plug/commit/3f00dfad4e20ba88472e315c90a25742bf178f8e
- https://github.com/elixir-plug/plug/commit/4167981747fe9ce75f374b94a28861ae950ea992
- https://github.com/elixir-plug/plug/commit/a6d1248659022749869963fd302687165ecf8c8b
- https://github.com/elixir-plug/plug/commit/eceb8315ce9a31ef784943a95a8624ebd1bc7e06
- https://github.com/elixir-plug/plug/commit/f26876aa67aaeb38e616638aa3efbcc2fe2906a5
- https://github.com/elixir-plug/plug/security/advisories/GHSA-wpmj-jh88-rpgm
- https://osv.dev/vulnerability/EEF-CVE-2026-56813
Raw JSON (NVD)
Show
{
"id": "CVE-2026-56813",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-56813",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-07-10T14:43:36.298825Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 2.1,
"Automatable": "NOT_DEFINED",
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:elixir-plug:plug:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/elixir-plug/plug",
"vendor": "elixir-plug",
"modules": [
"'Elixir.Plug.Conn.Cookies'",
"'Elixir.Plug.Conn'"
],
"product": "plug",
"versions": [
{
"status": "affected",
"version": "0.1.0",
"lessThan": "1.16.6",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.17.0",
"lessThan": "1.17.4",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.18.0",
"lessThan": "1.18.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.19.1",
"lessThan": "1.19.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.20.0",
"lessThan": "1.20.3",
"versionType": "semver"
}
],
"packageURL": "pkg:hex/plug",
"packageName": "plug",
"programFiles": [
"lib/plug/conn/cookies.ex"
],
"collectionURL": "https://repo.hex.pm",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.Plug.Conn.Cookies':encode/2"
},
{
"name": "'Elixir.Plug.Conn':put_resp_cookie/4"
}
]
},
{
"cpes": [
"cpe:2.3:a:elixir-plug:plug:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/elixir-plug/plug",
"vendor": "elixir-plug",
"modules": [
"'Elixir.Plug.Conn.Cookies'",
"'Elixir.Plug.Conn'"
],
"product": "plug",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "3f00dfad4e20ba88472e315c90a25742bf178f8e",
"status": "unaffected"
},
{
"at": "a6d1248659022749869963fd302687165ecf8c8b",
"status": "unaffected"
},
{
"at": "4167981747fe9ce75f374b94a28861ae950ea992",
"status": "unaffected"
},
{
"at": "149d9ed68fee0b4f77efd1e835ce5d785856697b",
"status": "unaffected"
},
{
"at": "eceb8315ce9a31ef784943a95a8624ebd1bc7e06",
"status": "unaffected"
}
],
"version": "f26876aa67aaeb38e616638aa3efbcc2fe2906a5",
"lessThan": "*",
"versionType": "git"
}
],
"packageURL": "pkg:github/elixir-plug/plug",
"packageName": "elixir-plug/plug",
"programFiles": [
"lib/plug/conn/cookies.ex"
],
"collectionURL": "https://github.com",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.Plug.Conn.Cookies':encode/2"
},
{
"name": "'Elixir.Plug.Conn':put_resp_cookie/4"
}
]
}
]
}
],
"published": "2026-07-10T13:16:20.663",
"references": [
{
"url": "https://cna.erlef.org/cves/CVE-2026-56813.html",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/149d9ed68fee0b4f77efd1e835ce5d785856697b",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/3f00dfad4e20ba88472e315c90a25742bf178f8e",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/4167981747fe9ce75f374b94a28861ae950ea992",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/a6d1248659022749869963fd302687165ecf8c8b",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/eceb8315ce9a31ef784943a95a8624ebd1bc7e06",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/commit/f26876aa67aaeb38e616638aa3efbcc2fe2906a5",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/elixir-plug/plug/security/advisories/GHSA-wpmj-jh88-rpgm",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-56813",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"description": [
{
"lang": "en",
"value": "CWE-141"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes.\n\nThe Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set-Cookie response header by interpolating the cookie value and its path, domain, same_site, and extra attributes directly into the header without neutralizing the ; delimiter that separates cookie attributes.\n\nAn application that places attacker-controlled data into a cookie value or attribute (for example via Plug.Conn.put_resp_cookie/4 when reflecting a username or preference) lets an attacker inject a ; to append or override cookie attributes (such as Domain and Path scope, or dropping the Secure and HttpOnly flags), enabling cookie tossing and session fixation. Carriage return, line feed, and null bytes are rejected by Plug.Conn header validation, so HTTP response splitting is not possible, but attribute injection through ; is not prevented.\n\nThis issue affects plug: from 0.1.0 before 1.16.6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.19.1 before 1.19.5, and from 1.20.0 before 1.20.3."
}
],
"lastModified": "2026-09-24T22:17:00.960",
"sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}