CWE-93— CRLF Injection
The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.— MITRE CWE catalog
235 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-93page 3 of 5
- CVE-2026-12357HIGHCVSS 7.2EG 7.22026-07-29
Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentica…
- CVE-2026-1299MEDIUMCVSS 6.0EG 6.02026-01-23
The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using …
- CVE-2026-13666LOWCVSS 3.5EG 3.52026-09-18
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write…
- CVE-2026-1467MEDIUMCVSS 5.3EG 6.12026-01-27
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the H…
- CVE-2026-1502MEDIUMCVSS 5.7EG 5.72026-04-10
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
- CVE-2026-15157MEDIUMCVSS 5.4EG 5.42026-07-29
undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8…
- CVE-2026-1527MEDIUMCVSS 4.6EG 4.62026-03-12
ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: * Inject arbitrary HTTP headers * Terminate the HTTP request prematurely and smugg…
- CVE-2026-1536MEDIUMCVSS 5.3EG 5.82026-01-28
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP …
- CVE-2026-15429HIGHCVSS 8.8EG 8.82026-07-14
A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. …
- CVE-2026-16313HIGHCVSS 7.6EG 7.62026-07-28
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplie…
- CVE-2026-16455MEDIUMCVSS 6.9EG 6.92026-08-13
In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to …
- CVE-2026-1714HIGHCVSS 8.6EG 8.62026-02-18
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and including, 3.3.2. This is due to the lack of validation…
- CVE-2026-19862MEDIUMCVSS 4.8EG 4.82026-09-06
The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users t…
- CVE-2026-20113MEDIUMCVSS 5.3EG 5.32026-03-25
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against…
- CVE-2026-21428HIGHCVSS 7.5EG 7.52026-01-01
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.0, the ``write_headers`` function does not check for CR & LF characters in user supplied headers, allowing untrusted header value to es…
- CVE-2026-22777HIGHCVSS 7.5EG 7.52026-01-10
ComfyUI-Manager is an extension designed to enhance the usability of ComfyUI. Prior to versions 3.39.2 and 4.0.5, an attacker can inject special characters into HTTP query parameters to add arbitrary configuration values to the config.ini …
- CVE-2026-23829MEDIUMCVSS 5.3EG 5.32026-01-19
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An at…
- CVE-2026-23953HIGHCVSS 8.7EG 8.72026-01-22
Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variabl…
- CVE-2026-2400MEDIUMCVSS 4.3EG 4.32026-04-14
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload.
- CVE-2026-2442MEDIUMCVSS 5.3EG 5.32026-03-28
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.0.7. This is due to the contact form h…
- CVE-2026-24489MEDIUMCVSS 5.3EG 5.32026-01-27
Gakido is a Python HTTP client focused on browser impersonation and anti-bot evasion. A vulnerability was discovered in Gakido prior to version 0.1.1 that allowed HTTP header injection through CRLF (Carriage Return Line Feed) sequences in …
- CVE-2026-26962MEDIUMCVSS 6.5EG 6.52026-04-02
Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds folded multipart part headers incorrectly. When a multipart header contains an obs-fold sequence, Rack preserves the e…
- CVE-2026-2717MEDIUMCVSS 5.5EG 5.52026-04-22
The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and including, 1.19.2. This is due to insufficient sanitization of custom header name and value fields before writing them to the Apache .htaccess…
- CVE-2026-28296MEDIUMCVSS 4.3EG 4.32026-02-26
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences …
- CVE-2026-28753LOWCVSS 3.7EG 3.72026-03-24
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP u…
- CVE-2026-29046HIGHCVSS 8.2EG 8.22026-03-06
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environment variables (HTTP_*). The parser did not strictly reject dangerous contr…
- CVE-2026-30227MEDIUMCVSS 5.3EG 5.32026-03-06
MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability i…
- CVE-2026-3234MEDIUMCVSS 4.3EG 4.32026-03-12
A flaw was found in mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeenc() function, allows a remote attacker to bypass input validation. By injecting CRLF sequences into the cluster configu…
- CVE-2026-32964MEDIUMCVSS 6.5EG 6.52026-04-20
SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead to arbitrary entries injected to the sys…
- CVE-2026-32993HIGHCVSS 8.3EG 8.32026-05-13
Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.
- CVE-2026-33128CRITICALCVSS 10.0EG 10.02026-03-20
H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injection due to missing newline sanitization in formatEventStreamMessage() an…
- CVE-2026-33606MEDIUMCVSS 4.8EG 4.82026-08-28
Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state o…
- CVE-2026-33635MEDIUMCVSS 4.3EG 4.32026-03-26
iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in version 2.0.0 and prior to version 2.12.2, .ics serialization does not properly sanitize URI property values, enabling IC…
- CVE-2026-34458HIGHCVSS 8.8EG 8.82026-05-05
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration restrictions (EditAdminOnly and ConfigPass…
- CVE-2026-34975HIGHCVSS 8.5EG 8.52026-04-06
Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability was discovered in SESService.ts, where user-supplied values for from.name, subject, custom header keys/values, and attach…
- CVE-2026-35504MEDIUMCVSS 5.5EG 5.52026-05-12
PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.
- CVE-2026-35517HIGHCVSS 8.8EG 8.82026-04-07
FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the upstream DNS servers conf…
- CVE-2026-35518HIGHCVSS 8.8EG 8.82026-04-07
FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS CNAME records configu…
- CVE-2026-35519HIGHCVSS 8.8EG 8.82026-04-07
FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS host record configura…
- CVE-2026-35520HIGHCVSS 8.8EG 8.82026-04-07
FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP lease time configura…
- CVE-2026-35521HIGHCVSS 8.8EG 8.82026-04-07
FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP hosts configuration …
- CVE-2026-35601MEDIUMCVSS 4.1EG 4.12026-04-10
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCalendar VTODO entries via raw string concatenation without applying RFC 5545 TEXT value escaping. User-controlled task tit…
- CVE-2026-3633MEDIUMCVSS 6.5EG 6.52026-03-17
A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line F…
- CVE-2026-3634MEDIUMCVSS 6.5EG 6.52026-03-17
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` f…
- CVE-2026-3848MEDIUMCVSS 5.0EG 5.02026-03-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to make unintended internal requests through proxy envi…
- CVE-2026-39394CRITICALCVSS 9.8EG 9.82026-04-08
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Install::index() controller reads the host POST parameter without any vali…
- CVE-2026-39849HIGHCVSS 8.8EG 8.82026-05-05
Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL accepted newline characters without validation, allowing an att…
- CVE-2026-39958CRITICALCVSS 9.1EG 9.12026-04-09
oma is a package manager for AOSC OS. Prior to 1.25.2, oma-topics is responsible for fetching metadata for testing repositories (topics) named "Topic Manifests" ({mirror}/debs/manifest/topics.json) from remote repository servers, registeri…
- CVE-2026-39983HIGHCVSS 8.6EG 8.62026-04-09
basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), l…
- CVE-2026-40530HIGHCVSS 8.0EG 8.02026-09-18
An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbit…
Map vulnerabilities like CWE-93 to your infrastructure
EchelonGraph correlates every CVE — across CWE-93 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →