CVE-2026-50576: CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in fbeta-GmbH ePA3-Service-OpenSource
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration does not neutralize CRLF characters in values used by app/vau/VAUProtokoll.py to construct VAU inner HTTP requests. The build_inner_header function interpolates the uri, host, accept_type, content_type, content_length, USER_AGENT, and insurant_id values into request lines and headers, including x-useragent and x-insurantid. An authenticated attacker who controls a value can inject additional headers into the inner request. Depending on ePA server handling, an injected x-insurantid header can expose another patient's records, and injected Authorization headers can bypass the intended authentication or authorization context. Session-derived USER_AGENT input can also poison requests across the session. This issue is fixed in version 1.3.0.
AI Analysis
Technical Summary
The ePA 3.x Integration component of fbeta-GmbH's ePA3-Service-OpenSource improperly neutralizes CRLF sequences in HTTP header values used by the build_inner_header function in app/vau/VAUProtokoll.py. This function interpolates user-controllable values such as uri, host, accept_type, content_type, content_length, USER_AGENT, and insurant_id into HTTP request lines and headers. An authenticated attacker controlling these values can inject additional headers, including x-insurantid and Authorization headers, potentially exposing other patients' medical records or bypassing authentication and authorization controls. The vulnerability is resolved in version 1.3.0.
Potential Impact
An authenticated attacker can exploit this vulnerability to inject arbitrary HTTP headers into inner requests, which may expose sensitive patient records or allow bypassing of authentication and authorization mechanisms. This compromises confidentiality and integrity of the affected system. There is no indication of availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
This vulnerability is fixed in version 1.3.0 of ePA3-Service-OpenSource. Users should upgrade to version 1.3.0 or later to remediate this issue. No other mitigation or temporary workaround is indicated.
CVE-2026-50576: CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in fbeta-GmbH ePA3-Service-OpenSource
Description
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration does not neutralize CRLF characters in values used by app/vau/VAUProtokoll.py to construct VAU inner HTTP requests. The build_inner_header function interpolates the uri, host, accept_type, content_type, content_length, USER_AGENT, and insurant_id values into request lines and headers, including x-useragent and x-insurantid. An authenticated attacker who controls a value can inject additional headers into the inner request. Depending on ePA server handling, an injected x-insurantid header can expose another patient's records, and injected Authorization headers can bypass the intended authentication or authorization context. Session-derived USER_AGENT input can also poison requests across the session. This issue is fixed in version 1.3.0.
CVSS v3.1
Score 6.8medium
Affected software
fbeta-GmbH
ePA3-Service-OpenSource
pkg:github/fbeta-gmbh/ePA3-Service-OpenSourceRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ePA 3.x Integration component of fbeta-GmbH's ePA3-Service-OpenSource improperly neutralizes CRLF sequences in HTTP header values used by the build_inner_header function in app/vau/VAUProtokoll.py. This function interpolates user-controllable values such as uri, host, accept_type, content_type, content_length, USER_AGENT, and insurant_id into HTTP request lines and headers. An authenticated attacker controlling these values can inject additional headers, including x-insurantid and Authorization headers, potentially exposing other patients' medical records or bypassing authentication and authorization controls. The vulnerability is resolved in version 1.3.0.
Potential Impact
An authenticated attacker can exploit this vulnerability to inject arbitrary HTTP headers into inner requests, which may expose sensitive patient records or allow bypassing of authentication and authorization mechanisms. This compromises confidentiality and integrity of the affected system. There is no indication of availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
This vulnerability is fixed in version 1.3.0 of ePA3-Service-OpenSource. Users should upgrade to version 1.3.0 or later to remediate this issue. No other mitigation or temporary workaround is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-04T21:34:34.427Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a849468c6e8be03328570ee
Added to database: 08/18/2026, 17:20:40 UTC
Last enriched: 08/18/2026, 17:35:27 UTC
Last updated: 10/02/2026, 14:46:08 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.