{"id":"CVE-2026-35515","aliases":["GHSA-36xv-jgw5-4q75"],"url":"https://o3.security/vulnerability/CVE-2026-35515","summary":"@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\n[`SseStream._transform()`](https://github.com/nestjs/nest/blob/dea5279ef8fcb568de158003e4281759a2cd7675/packages/core/router/sse-stream.ts) interpolates `message.type` and `message.id` directly into Server-Sent Events text protocol output without sanitizing newline characters (`\\r`, `\\n`). Since the SSE protocol treats both `\\r` and `\\n` as field delimiters and `\\n\\n` as event boundaries, an attacker who can influence these fields through upstream data sources can inject arbitrary SSE events, spoof event types, and corrupt reconnection state. Spring Framework's own security patch ([6e97587](https://github.com/spring-projects/spring-framework/commit/6e9758700a4946be1dca85ca937ef2603e291301)) validates these same fields (`id`, `event`) for the same reason.\n\nActual impact:\n\n- **Event spoofing**: Attacker forges SSE events with arbitrary `event:` types, causing client-side `EventSource.addEventListener()` callbacks to fire for wrong event types.\n- **Data injection**: Attacker injects arbitrary `data:` payloads, potentially triggering XSS if the client renders SSE data as HTML without sanitization.\n- **Reconnection corruption**: Attacker injects `id:` fields, corrupting the `Last-Event-ID` header on reconnection, causing the client to miss or replay events.\n- **Attack precondition**: Requires the developer to map user-influenced data to the `type` or `id` fields of SSE messages. Direct HTTP request input does not reach these fields without developer code bridging the gap.\n-\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nPatched in `@nestjs/core@11.1.18`","published":"2026-04-07T15:06:10.619Z","modified":"2026-08-12T03:51:48.636495148Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@nestjs/core","fixedVersion":"11.1.18"}],"fix":{"url":"https://github.com/nestjs/nest/pull/16686","label":"nestjs/nest#16686"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35515.json"},{"type":"ADVISORY","url":"https://github.com/nestjs/nest/security/advisories/GHSA-36xv-jgw5-4q75"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35515"},{"type":"WEB","url":"https://github.com/nestjs/nest/pull/16686"},{"type":"WEB","url":"https://github.com/nestjs/nest/commit/83558ae774a990a7916141d3abe0b6548ff3a8b2"},{"type":"PACKAGE","url":"https://github.com/nestjs/nest"},{"type":"WEB","url":"https://github.com/nestjs/nest/releases/tag/v11.1.18"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.636495148Z"}}