Junglewise Threat Intelligence

CVE-2026-41683: i18next-http-middleware CRLF injection in Content-Language header

CVE-2026-41683 · Severity: high · CVSS 8.6 · Published 2026-05-08

Technologies: I18next-Http-Middleware. Vendors: npm.

Executive brief

i18next-http-middleware is a tool used by web developers to handle language detection in Node.js and Deno applications. A security flaw allows attackers to inject malicious characters into the website's response headers. Depending on the server configuration, this can lead to the site crashing (denial of service) or allow attackers to perform advanced attacks like session hijacking and redirecting users to malicious websites.

Technical details

i18next-http-middleware prior to version 3.9.3 is vulnerable to HTTP response splitting and denial of service. The middleware used an HTML-entity encoder (utils.escape) that failed to strip carriage return (CR) and line feed (LF) characters from user-provided language parameters. When paired with older versions of i18next (< 19.5.0), these raw CRLF sequences are passed directly to res.setHeader(). In Node.js versions < 14.6.0, this allows for HTTP response splitting, enabling header injection, cache poisoning, and reflected XSS. In Node.js versions >= 14.6.0, the same exploit triggers an unhandled ERR_INVALID_CHAR exception, leading to a denial of service. Version 3.9.3 fixes this by introducing a new sanitization function and tightening XSS regex filters.

Affected products

  • i18next i18next-http-middleware < 3.9.3

Timeline

  • 2026-04-18: advisory: GitHub Security Advisory published
  • 2026-05-08: disclosed: CVE published to NVD
  • 2026-05-08: patched: Fix released in version 3.9.3

References

Related threats