A vulnerability tracked as CVE-2026-48598 was disclosed in the Elixir HTTP client library elixir-tesla, where multipart serialization allowed attacker-controlled metadata to break Content-Disposition headers and alter outbound HTTP requests. The flaw affects Tesla 0.8.0 through before 1.18.3 and stems from unsafe interpolation of multipart disposition parameters in the private part_headers_for_disposition/1 function. If an application accepts untrusted filenames or related metadata and passes them into multipart helpers such as Tesla.Multipart.add_file/3 or add_file_content/4, an attacker could inject headers, smuggle body content, or spoof multipart metadata sent to downstream services.
The project addressed the issue by adding stricter validation to multipart entry points and enforcing RFC-compliant grammar for content-type parameters, multipart part headers, and quoted-string fields including names and filenames. The fix rejects unsafe characters such as CR, LF, NUL, DEL, invalid header characters, and semicolons in content-type parameters, with tests added for header injection and parameter smuggling scenarios. Although the reported severity is low at CVSS 2.1 and exploitation requires a specific application flow involving untrusted file metadata, the flaw could still expose downstream systems to forged requests or secondary trust-boundary failures if multipart metadata is relied upon.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-48598 was publicly reported as a multipart part header injection and request smuggling vulnerability in elixir-tesla affecting versions 0.8.0 through before 1.18.3. The disclosure states that version 1.18.3 fixes the issue through stricter validation after earlier sanitizer work and an RFC-compliant whitelist implementation.
A commit in the elixir-tesla/tesla project added validation to Tesla.Multipart entry points to block unsafe characters and enforce RFC grammar, addressing header injection and multipart parameter smuggling risks. The change was authored by Yordis Prieto, merged into master, tagged v1.20.0, and included tests for injection and smuggling cases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.