CVE-2026-44217

MEDIUM

sse-channel: SSE Injection via unsanitized event fields

Title source: cna
STIX 2.1

Description

sse-channel is an SSE-implementation which can be used to any node.js http request/response stream. Prior to 4.0.1, implementations that allow user-provided values to be passed to event, retry or id fields are susceptible to event spoofing, where an attacker could inject arbitrary messages into the stream. This vulnerability is fixed in 4.0.1.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/rexxars/sse-channel/issues/42

Scores

CVSS v4 6.6
EPSS 0.0002
EPSS Percentile 5.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-93
Status published
Products (2)
npm/sse-channel 0 - 4.0.1npm
rexxars/sse-channel < 4.0.1
Published May 12, 2026
Tracked Since May 13, 2026