PT-2026-29997 · Electron · Electron

Vertedinde

·

Published

2026-04-03

·

Updated

2026-04-04

·

CVE-2026-34767

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Electron versions prior to 38.8.6, 39.8.3, 40.8.3, and 41.0.3
Description Applications using Electron that register custom protocol handlers via protocol.handle() / protocol.registerSchemesAsPrivileged() or modify response headers via webRequest.onHeadersReceived may be susceptible to HTTP response header injection if attacker-controlled input is reflected into a response header name or value. An attacker influencing a header value could inject additional response headers, potentially affecting cookies, content security policy, or cross-origin access controls. Applications that do not reflect external input into response headers are not affected.
Recommendations Versions prior to 38.8.6: Validate or sanitize any untrusted input before including it in a response header name or value. Versions prior to 39.8.3: Validate or sanitize any untrusted input before including it in a response header name or value. Versions prior to 40.8.3: Validate or sanitize any untrusted input before including it in a response header name or value. Versions prior to 41.0.3: Validate or sanitize any untrusted input before including it in a response header name or value.

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-34767
GHSA-4P4R-M79C-WQ3V

Affected Products

Electron