Junglewise Threat Intelligence

CVE-2026-34715: vshakitskiy ewe HTTP response splitting in encoder

CVE-2026-34715 · Severity: medium · CVSS 5.3 · Published 2026-04-02

Executive brief

ewe is a web server for the Gleam programming language. A security flaw in how it handles website responses allows attackers to inject malicious content into the data sent to users' browsers. This could be used to redirect users to malicious sites, corrupt web caches, or perform cross-site scripting (XSS) attacks.

Technical details

The vulnerability is an Improper Neutralization of CRLF Sequences (CWE-113) in the HTTP response encoder. Specifically, the `encode_headers` function in `src/ewe/internal/encoder.gleam` directly interpolates header keys and values into the raw HTTP byte stream using string interpolation without sanitizing carriage return (CR) or line feed (LF) characters. An attacker can exploit this by providing input containing `%0d%0a` sequences to an application that reflects user input in response headers (such as a redirect URL). This allows the attacker to terminate the current header early and inject arbitrary headers or even a second HTTP response body. The issue is resolved in version 3.0.6 by implementing sanitization for outgoing headers.

Affected products

  • vshakitskiy ewe < 3.0.6

Timeline

  • 2026-03-25: patched: Fix committed to repository
  • 2026-03-30: advisory: GitHub Security Advisory published
  • 2026-04-02: disclosed: CVE published to NVD

References