{"id":"GHSA-36xv-jgw5-4q75","summary":"@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\n[`SseStream._transform()`](https://github.com/nestjs/nest/blob/dea5279ef8fcb568de158003e4281759a2cd7675/packages/core/router/sse-stream.ts) interpolates `message.type` and `message.id` directly into Server-Sent Events text protocol output without sanitizing newline characters (`\\r`, `\\n`). Since the SSE protocol treats both `\\r` and `\\n` as field delimiters and `\\n\\n` as event boundaries, an attacker who can influence these fields through upstream data sources can inject arbitrary SSE events, spoof event types, and corrupt reconnection state. Spring Framework's own security patch ([6e97587](https://github.com/spring-projects/spring-framework/commit/6e9758700a4946be1dca85ca937ef2603e291301)) validates these same fields (`id`, `event`) for the same reason.\n\nActual impact:\n\n- **Event spoofing**: Attacker forges SSE events with arbitrary `event:` types, causing client-side `EventSource.addEventListener()` callbacks to fire for wrong event types.\n- **Data injection**: Attacker injects arbitrary `data:` payloads, potentially triggering XSS if the client renders SSE data as HTML without sanitization.\n- **Reconnection corruption**: Attacker injects `id:` fields, corrupting the `Last-Event-ID` header on reconnection, causing the client to miss or replay events.\n- **Attack precondition**: Requires the developer to map user-influenced data to the `type` or `id` fields of SSE messages. Direct HTTP request input does not reach these fields without developer code bridging the gap.\n-\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nPatched in `@nestjs/core@11.1.18`","aliases":["CVE-2026-35515"],"modified":"2026-09-10T03:50:42.305999581Z","published":"2026-04-06T17:59:51Z","database_specific":{"nvd_published_at":"2026-04-07T16:16:27Z","cwe_ids":["CWE-74"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-06T17:59:51Z"},"references":[{"type":"WEB","url":"https://github.com/nestjs/nest/security/advisories/GHSA-36xv-jgw5-4q75"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35515"},{"type":"WEB","url":"https://github.com/nestjs/nest/pull/16686"},{"type":"WEB","url":"https://github.com/nestjs/nest/commit/83558ae774a990a7916141d3abe0b6548ff3a8b2"},{"type":"PACKAGE","url":"https://github.com/nestjs/nest"},{"type":"WEB","url":"https://github.com/nestjs/nest/releases/tag/v11.1.18"}],"affected":[{"package":{"name":"@nestjs/core","ecosystem":"npm","purl":"pkg:npm/%40nestjs/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.1.18"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 11.1.17","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-36xv-jgw5-4q75/GHSA-36xv-jgw5-4q75.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:N"}]}