← Back to CVE List
Vulnerability Intelligence Report
HTTP response splitting and DoS in i18next-http-middleware via unsanitised Content-Language header

CVE-2026-41683

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware wrote user-controlled language values into the Content-Language response header after passing them through utils.escape(), which is an HTML-entity encoder that does not strip carriage return, line feed, or other control characters. When the application used an older i18next (< 19.5.0) that still exercised the backward-compatibility fallback at LanguageDetector.js:100 or otherwise produced a raw detected value, CRLF sequences in the attacker-controlled lng parameter reached res.setHeader('Content-Language', ...) verbatim. This issue has been patched in version 3.9.3.

No Active Exploit Signals
CVSS Base Score
8.6
HIGH
Exploitability:3.9
Impact Score:4.8
EPSS Probability:0.33%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-79 ↗CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-113 ↗CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

Affected Products & Versions

Vendor Product Affected Versions
i18next i18next-http-middleware < 3.9.3 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.327%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-04-22T03:53:24
Published2026-05-08T15:27:05
Last Updated2026-05-08T23:29:00

LINK COPIED TO CLIPBOARD