CVE-2018-1000883: Plug Project Plug
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack appear to be exploitable via Crafting a value to be sent as a cookie. This vulnerability appears to have been fixed in >= 1.3.5 or ~> 1.2.5 or ~> 1.1.9 or ~> 1.0.6.
Affected products
- Plug Project Plug: after 1.0.6, up to and including 1.1.9; after 1.1.9, up to and including 1.2.5; from 1.2.5, before 1.3.5 (fixed in 1.3.5); from 1.3.5
Published 2018-12-20. Last modified 2026-06-17.