A vulnerability marked as critical has been reported in wojtekmach req up to 0.5.x. The impacted element is an unknown function in the library lib/req/utils.ex. The manipulation leads to crlf injection.
This vulnerability is listed as CVE-2026-49756. The attack must be carried out locally. There is no available exploit.
It is suggested to upgrade the affected component.