CVE-2025-53094
CVE-2025-53094 is a high-severity vulnerability with a CVSS 4.0 base score of 8.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-93.
Key facts
- Severity: High (CVSS 4.0 base score 8.7)
- EPSS exploit prediction: 0% (35th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-19427
- Weakness: CWE-93
- Published:
- Last modified:
Description
ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage Return Line Feed) injection vulnerability exists in the construction and output of HTTP headers within `AsyncWebHeader.cpp`. Unsanitized input allows attackers to inject CR (`\r`) or LF (`\n`) characters into header names or values, leading to arbitrary header or response manipulation. Manipulation of HTTP headers and responses can enable a wide range of attacks, making the severity of this vulnerability high. A fix is available at pull request 211 and is expected to be part of version 3.7.9.
Frequently asked questions
- What is CVE-2025-53094?
- ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage Return Line Feed) injection vulnerability exists in the construction and output of HTTP headers within `AsyncWebHeader.cpp`. Unsanitized input allows attackers to inject CR (`\r`) or LF (`\n`) characters into header names or values, leading to arbitrary header or response manipulation. Manipulation of HTTP headers and responses can enable a wide range of attacks, making the severity of this vulnerability high. A fix is available at pull request 211 and is expected to be part of version 3.7.9.
- How severe is CVE-2025-53094?
- CVE-2025-53094 has a CVSS 4.0 base score of 8.7, rated high severity.
- Is CVE-2025-53094 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (35th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2025-53094?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2025-53094 have an EU (EUVD) identifier?
- Yes. CVE-2025-53094 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-19427.
- When was CVE-2025-53094 published?
- CVE-2025-53094 was published on 2025-06-27 and last updated on 2026-06-17.
References
- https://github.com/ESP32Async/ESPAsyncWebServer/blob/1095dfd1ecf1a903aede29854232af1b24f089b1/src/AsyncWebHeader.cpp#L6-L32
- https://github.com/ESP32Async/ESPAsyncWebServer/pull/211
- https://github.com/ESP32Async/ESPAsyncWebServer/security/advisories/GHSA-87j8-6f7g-h8wh
Other CWE-93 (CRLF Injection) vulnerabilities
- CVE-2026-77550 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability…
- CVE-2024-51501 — Critical (CVSS 10.0): Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit…
- CVE-2026-100717 — Critical (CVSS 9.9): froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return…
- CVE-2026-90937 — Critical (CVSS 9.9): froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated…
- CVE-2026-70615 — Critical (CVSS 9.9): boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users…
- CVE-2026-45372 — Critical (CVSS 9.9): cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's…