CVE-2026-34767 describes an HTTP response header injection vulnerability in the Electron framework, affecting applications that register custom protocol handlers or modify response headers if attacker-controlled input is reflected. Rated Medium (CVSS 5.9) with High Attack Complexity, this flaw could allow remote attackers to inject headers, impacting cookies, Content Security Policy, or cross-origin access controls. Successful exploitation requires user interaction and specific application configurations. There is currently no evidence of active exploitation, no public exploit code available, and minimal community discussion. Affected Electron versions prior to 38.8.6, 39.8.3, 40.8.3, and 41.0.3 should be updated.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 38.8.6CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
>= 39.0.0, < 39.8.3CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
>= 40.0.0, < 40.8.3CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
>= 41.0.0, < 41.0.3CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.