Skip to main content
EPSS 0.5%top 60%

CVE-2026-50576: CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in fbeta-GmbH ePA3-Service-OpenSource

0
Medium
VulnerabilityCVE-2026-50576cvecve-2026-50576cwe-113
Published: 08/18/2026 (08/18/2026, 16:49:43 UTC)
Source: CVE Database V5
Vendor/Project: fbeta-GmbH
Product: ePA3-Service-OpenSource

Description

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration does not neutralize CRLF characters in values used by app/vau/VAUProtokoll.py to construct VAU inner HTTP requests. The build_inner_header function interpolates the uri, host, accept_type, content_type, content_length, USER_AGENT, and insurant_id values into request lines and headers, including x-useragent and x-insurantid. An authenticated attacker who controls a value can inject additional headers into the inner request. Depending on ePA server handling, an injected x-insurantid header can expose another patient's records, and injected Authorization headers can bypass the intended authentication or authorization context. Session-derived USER_AGENT input can also poison requests across the session. This issue is fixed in version 1.3.0.

CVSS v3.1

Score 6.8medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected software

fbeta-GmbH

ePA3-Service-OpenSource

Affected versions
<1.3.0
GitHub Actionsmore threats →ai
fbeta-gmbh/ePA3-Service-OpenSource
pkg:github/fbeta-gmbh/ePA3-Service-OpenSource
Affected versions
<1.3.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/18/2026, 17:35:27 UTC

Technical Analysis

The ePA 3.x Integration component of fbeta-GmbH's ePA3-Service-OpenSource improperly neutralizes CRLF sequences in HTTP header values used by the build_inner_header function in app/vau/VAUProtokoll.py. This function interpolates user-controllable values such as uri, host, accept_type, content_type, content_length, USER_AGENT, and insurant_id into HTTP request lines and headers. An authenticated attacker controlling these values can inject additional headers, including x-insurantid and Authorization headers, potentially exposing other patients' medical records or bypassing authentication and authorization controls. The vulnerability is resolved in version 1.3.0.

Potential Impact

An authenticated attacker can exploit this vulnerability to inject arbitrary HTTP headers into inner requests, which may expose sensitive patient records or allow bypassing of authentication and authorization mechanisms. This compromises confidentiality and integrity of the affected system. There is no indication of availability impact. No known exploits in the wild have been reported.

Mitigation Recommendations

This vulnerability is fixed in version 1.3.0 of ePA3-Service-OpenSource. Users should upgrade to version 1.3.0 or later to remediate this issue. No other mitigation or temporary workaround is indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-04T21:34:34.427Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a849468c6e8be03328570ee

Added to database: 08/18/2026, 17:20:40 UTC

Last enriched: 08/18/2026, 17:35:27 UTC

Last updated: 10/02/2026, 14:46:08 UTC

Views: 64

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses