Where: oxyroute/sse.py:31-33 (_format_sse_event).
ev.event and ev.id are interpolated directly into event: {ev.event} / id: {ev.id} lines without stripping \n/\r. If either value comes from user input, a newline lets the attacker inject arbitrary extra SSE fields (e.g. a fake data: line) or start a new event, breaking the intended event boundary.
Fix direction: reject or strip \r/\n from event and id the same way data is already split per-line.
Where:
oxyroute/sse.py:31-33(_format_sse_event).ev.eventandev.idare interpolated directly intoevent: {ev.event}/id: {ev.id}lines without stripping\n/\r. If either value comes from user input, a newline lets the attacker inject arbitrary extra SSE fields (e.g. a fakedata:line) or start a new event, breaking the intended event boundary.Fix direction: reject or strip
\r/\nfromeventandidthe same waydatais already split per-line.