Impact
Improper neutralization of parameter delimiters in elixir‑plug plug creates a CWE‑141 vulnerability that allows an attacker to inject or override HTTP cookie attributes. The Plug.Conn.Cookies.encode/2 function interpolates cookie values and attributes directly into the Set‑Cookie header without neutralizing the ';' delimiter that separates cookie attributes. When attacker‑controlled data is inserted into a cookie value or attribute—for example via Plug.Conn.put_resp_cookie—the attacker can append or replace attributes such as Domain, Path, Secure, or HttpOnly, enabling cookie tossing, session fixation, or other session‑related attacks. Header validation blocks response‑splitting by rejecting carriage return, line feed, and null bytes, but it does not neutralize the ';', leaving the injection vector open.
Affected Systems
The vulnerability affects the elixir‑plug plug library across all versions prior to 1.16.6, 1.17.4, 1.18.5, 1.19.5, and 1.20.3. Applications built with Plug that pass untrusted data into Plug.Conn.put_resp_cookie/4 or Plug.Conn.Cookies.encode/2 will be impacted.
Risk and Exploitability
The CVSS score of 2.1 classifies this issue as low severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to influence cookie values or attributes that the application sends back to the client, and existing header validation blocks response splitting. While no public exploits have been reported, the risk remains theoretical, but mitigation is recommended due to the potential impact on session integrity.
OpenCVE Enrichment