EventSource Message Injection Vulnerability in EventSource Encoder by Rexxars
CVE-2026-44214

5.8MEDIUM

Key Information:

Vendor

Rexxars

Vendor
CVE Published:
26 May 2026

What is CVE-2026-44214?

The eventsource-encoder library prior to version 1.0.2 is vulnerable to message injection due to a lack of sanitization for event and ID fields in EventSource messages. Attackers can exploit this vulnerability by controlling these fields, enabling them to inject arbitrary line terminators. This can lead to the crafting of fraudulent Server-Sent Events (SSE) fields or entire messages within a stream, posing a significant security risk. This vulnerability was addressed in version 1.0.2, which includes the necessary sanitization measures to prevent such attacks.

Affected Version(s)

eventsource-encoder < 1.0.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.