---
cve: "CVE-2026-54163"
severity: "MEDIUM"
cvss: 4.7
epss: "17%"
vendor: "GitHub"
kev: false
exploited: false
published: "2026-07-17 21:17:08"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-14T06:52:15+02:00"
---

# CVE-2026-54163

> 4.7 MEDIUM · 🧪 PoC

## Beschreibung

secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and build_report_to_directive interpolate caller-supplied strings without scrubbing ;, \r, or \n. When untrusted input reaches SecureHeaders.override_content_security_policy_directives or append APIs for :sandbox, :plugin_types, or :report_to, an attacker can inject a CSP directive such as script-src 'unsafe-inline' * before the legitimate script-src, enabling XSS reachability through these sinks or CSP report exfiltration. This issue is fixed in version 7.3.0.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- 286a79dea80c6a9be4ca93e0f284c923cf77e539 (Commit)
- 65e2b4887eb3aea4184d078ef1a949b59977d29f (Commit)

## Referenzen

- <https://github.com/github/secure_headers/security/advisories/GHSA-rqq5-2gf9-4w4q>
- <https://github.com/github/secure_headers/commit/286a79dea80c6a9be4ca93e0f284c923cf77e539>
- <https://github.com/github/secure_headers/releases/tag/v7.3.0>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-54163) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
