THREAT OPS › Threat News › [GHSA] GHSA-px9f-whj3-246m (medium) — Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
[GHSA] GHSA-px9f-whj3-246m (medium) — Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
GHSA-px9f-whj3-246m Severity: medium CVE: CVE-2026-49756
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
### Summary
Req's multipart form encoder interpolates the per-part `name`, `filename`, and `content_type` directly into the part headers without escaping. An attacker who can influence any of those values can inject CRLF-separated header lines,
Indicators of compromise
- CVE-2026-49756cve
Original source: https://github.com/advisories/GHSA-px9f-whj3-246m