tesla
The flexible HTTP client library for Elixir, with support for middleware and multiple adapters.
Activity
- Latest release
- 1w ago
- Total releases
- 79
- Cadence
- ~18 days
- Last 12 months
- 11
Reach
- Downloads
- 73.5M
- Stars
- 2.1k
Details
- License
- MIT
- First release
- Apr 06, 2015
| Version | Released | |
|---|---|---|
1.21.3
patch
|
1.21.3
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.21.2
patch
|
1.21.2
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.21.1
patch
|
1.21.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.21.0
minor
|
1.21.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.20.0
minor
|
1.20.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.18.3
patch
|
1.18.3
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.18.2
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.18.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.18.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.17.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.16.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.15.3
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.15.2
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.15.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.15.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.14.3
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.14.2
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.14.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.14.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.13.2
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.13.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.13.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.12.3
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.12.2
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.12.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.12.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.11.2
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.11.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.11.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.10.3
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.10.2
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.10.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.10.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.9.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.8.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.8.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.7.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.6.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.6.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.5.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.5.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.4.4
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.4.3
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.4.2
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.4.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.4.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.3.3
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.3.2
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.3.1
patch
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
1.3.0
minor
5 CVEs
CVE-2026-48598
GHSA-28jh-g32x-v9v4
EEF-CVE-2026-48598
Jul 10, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
Local
Low
None
None
Summary
Details
The default-filename path in PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate disposition parameter values before passing them to the multipart API, rejecting any value that contains Resources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48597
GHSA-h74c-q9j7-mpcm
EEF-CVE-2026-48597
Jul 10, 2026
Tesla vulnerable to atom exhaustion via untrusted URL scheme
High
Network
Low
None
None
SummaryIn the Mint adapter for the Tesla HTTP client library, DetailsVulnerable call ( The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must use References
Affected versions
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
+ 32 more Show less
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48595
GHSA-9m9w-gxf7-rh8m
EEF-CVE-2026-48595
Jul 10, 2026
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
High
Network
Low
None
None
Summary
DetailsThe filter list in An attacker who can control a PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using WorkaroundsNormalize all header keys to lowercase before passing them to Tesla. Use Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48594
GHSA-mc85-72gr-vm9f
EEF-CVE-2026-48594
Jul 10, 2026
Tesla has decompression bomb on response body
High
Network
Low
None
None
SummaryAny Tesla client pipeline that includes Details
PoC
ImpactHigh severity (CVSS v4.0: 8.2). Any application using ConfigurationsThe application must include Resources
Affected versions
0.10.0
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
+ 44 more Show less
1.10.2
1.10.3
1.11.0
1.11.1
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-48596
GHSA-q7jx-v53g-848w
EEF-CVE-2026-48596
Jul 10, 2026
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Low
Local
Low
None
None
Summary
Details
The precondition is that untrusted input reaches PoC
ImpactLow severity (CVSS v4.0: 2.1). Any application using WorkaroundsValidate content-type parameter strings before passing them to Reesources
Affected versions
0.10.0
0.8.0
0.9.0
1.0.0
1.0.0-beta.1
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.11.1
+ 40 more Show less
1.11.2
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
Fixed in
1.18.3
References
Updated Jul 10, 2026 · Source: OSV.dev |