Junglewise Threat Intelligence

CVE-2026-44214: rexxars eventsource-encoder CRLF injection in event and id fields

CVE-2026-44214 · Severity: medium · CVSS 5.8 · Published 2026-05-26

Executive brief

The eventsource-encoder library, used to format Server-Sent Events (SSE) for web applications, is vulnerable to event injection. An attacker who can control the 'event' or 'id' fields can inject line breaks to forge fake messages or modify the event stream. This could allow an attacker to trigger unauthorized actions in a user's browser by spoofing high-privilege events or rerouting data to incorrect handlers.

Technical details

The vulnerability is a CRLF injection (CWE-93) within the `encodeMessage` function in `src/encode.ts`. The library interpolates the `event` and `id` fields directly into the output stream without checking for line terminators (\n, \r, or \r\n). Because the SSE specification uses these characters as delimiters, an attacker providing a crafted string containing these characters can terminate the current field prematurely and inject new fields such as `data:`, `retry:`, or entirely new events. This allows for event spoofing and overriding the client's `Last-Event-ID`. The issue is fixed in version 1.0.2 by validating that these fields do not contain line terminators.

Affected products

  • rexxars eventsource-encoder <= 1.0.1

Timeline

  • 2026-05-05: disclosed: Advisory published by maintainer
  • 2026-05-08: advisory: GitHub Advisory published
  • 2026-05-26: advisory: NVD published CVE-2026-44214
  • 2026-05-08: patched: Fixed in version 1.0.2

References