Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m9g3-3g99-mhpx | eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields |
Thu, 28 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:rexxars:eventsource-encoder:*:*:*:*:*:node.js:*:* |
Wed, 27 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rexxars
Rexxars eventsource-encoder |
|
| Vendors & Products |
Rexxars
Rexxars eventsource-encoder |
Tue, 26 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage before serializing them. An attacker who controls either field can inject arbitrary Server-Sent Events line terminators (\n, \r, or \r\n) and thereby forge additional SSE fields or entire messages on the stream. This vulnerability is fixed in 1.0.2. | |
| Title | eventsource-encoder: SSE event injection via unsanitized event and id fields | |
| Weaknesses | CWE-113 CWE-93 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-27T13:19:45.558Z
Reserved: 2026-05-05T15:13:47.572Z
Link: CVE-2026-44214
Updated: 2026-05-27T13:19:39.824Z
Status : Analyzed
Published: 2026-05-26T20:16:19.803
Modified: 2026-06-17T10:50:22.090
Link: CVE-2026-44214
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:08:41Z
Github GHSA