Improper Output Neutralization for Logs in Zulip Server - #VU151558
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to forge or obscure log entries.
The vulnerability exists due to improper output neutralization for logs in the /report/csp_violations endpoint when processing crafted CSP violation reports. A remote attacker can submit a crafted report containing control characters to forge or obscure log entries.
The endpoint is unauthenticated.