elixir-tesla records
5 published records for vendor elixir-tesla.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')1
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-178 Improper Handling of Case Sensitivity1
- CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2026-48594No exploit | Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compressionelixir-tesla · tesla · CWE-409 | High8.2 | — | 0.7% | Jun 2, 2026 |
32Monitor | CVE-2026-48595No exploit | Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirectselixir-tesla · tesla · CWE-178 | High8.2 | — | 0.7% | Jun 2, 2026 |
32Monitor | CVE-2026-48597No exploit | Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mintelixir-tesla · tesla · CWE-770 | High8.2 | — | 0.6% | Jun 2, 2026 |
8Monitor | CVE-2026-48596No exploit | CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injectionelixir-tesla · tesla · CWE-113 | Low2.1 | — | 0.3% | Jun 2, 2026 |
8Monitor | CVE-2026-48598Proof of concept | CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injectionelixir-tesla · tesla · CWE-116 | Low2.1 | — | 0.3% | Jun 2, 2026 |
- CVE-2026-4859432Monitor
Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
HighCVSS 8.2No exploitEPSS 1%elixir-tesla · teslaJun 2, 2026
- CVE-2026-4859532Monitor
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
HighCVSS 8.2No exploitEPSS 1%elixir-tesla · teslaJun 2, 2026
- CVE-2026-4859732Monitor
Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint
HighCVSS 8.2No exploitEPSS 1%elixir-tesla · teslaJun 2, 2026
- CVE-2026-485968Monitor
CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection
LowCVSS 2.1No exploitEPSS 0%elixir-tesla · teslaJun 2, 2026
- CVE-2026-485988Monitor
CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection
LowCVSS 2.1Proof of conceptEPSS 0%elixir-tesla · teslaJun 2, 2026