CWE-93: CRLF Injection — known CVE vulnerabilities
CVEs classified under CWE-93 (CRLF Injection), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-77550 — CVSS 10.0 (critical): A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain…
CVE-2024-51501: Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit attributes (Header…
CVE-2026-100717 — CVSS 9.9 (critical): froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed…
CVE-2026-90937 — CVSS 9.9 (critical): froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject…
CVE-2026-70615 — CVSS 9.9 (critical): boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation…
CVE-2026-45372 — CVSS 9.9 (critical): cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an…
CVE-2026-84372 — CVSS 9.8 (critical): Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on…
CVE-2026-82854 — CVSS 9.8 (critical): Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes…
CVE-2026-59313 — CVSS 9.8 (critical): Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring…
CVE-2026-47890 — CVSS 9.8 (critical): Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring…
CVE-2026-72590 — CVSS 9.8 (critical): An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject…
CVE-2026-11362 — CVSS 9.8 (critical): DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise…
CVE-2026-75925 — CVSS 9.6 (critical): Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM…
CVE-2026-82973 — CVSS 9.4 (critical): Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote…
CVE-2025-40671: SQL injection vulnerability in AES Multimedia's Gestnet v1.07. This vulnerability allows an attacker to retrieve, create, update and delete…
CVE-2026-44092 — CVSS 9.1 (critical): An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it…
CVE-2026-11373 — CVSS 9.1 (critical): Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol…
CVE-2026-50638 — CVSS 9.1 (critical): Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and…
CVE-2026-9270 — CVSS 9.1 (critical): DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing…
CVE-2026-39958 — CVSS 9.1 (critical): oma is a package manager for AOSC OS. Prior to 1.25.2, oma-topics is responsible for fetching metadata for testing repositories (topics)…
CVE-2026-77549 — CVSS 9.0 (critical): A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences…
CVE-2026-48019 — CVSS 8.9 (high): Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email…
CVE-2026-55159 — CVSS 8.8 (high): luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior…
CVE-2026-15429 — CVSS 8.8 (high): A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled…
CVE-2026-39849 — CVSS 8.8 (high): Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the…
CVE-2026-34458 — CVSS 8.8 (high): Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection…
CVE-2026-5140 — CVSS 8.8 (high): Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute…
CVE-2025-28357 — CVSS 8.8 (high): A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supplying a crafted…
CVE-2025-8715 — CVSS 8.8 (high): Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time…
CVE-2021-39172 — CVSS 8.8 (high): Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin)…
CVE-2026-23953 — CVSS 8.7 (high): Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a…
CVE-2025-53094: ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and…
CVE-2026-54511 — CVSS 8.6 (high): LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue()…
CVE-2026-39983 — CVSS 8.6 (high): basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path…
CVE-2026-1714 — CVSS 8.6 (high): The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to…
CVE-2026-41230 — CVSS 8.5 (high): Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types…
CVE-2026-34975 — CVSS 8.5 (high): Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability was discovered in…
CVE-2024-36459: A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and…
CVE-2026-71573 — CVSS 8.3 (high): Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented…
CVE-2026-32993 — CVSS 8.3 (high): Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject…
CVE-2026-77634: CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release…
CVE-2026-50637 — CVSS 8.2 (high): Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and…
CVE-2026-46720 — CVSS 8.2 (high): Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines…
CVE-2025-59151 — CVSS 8.2 (high): Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application…
CVE-2023-38551 — CVSS 8.2 (high): A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code…
CVE-2024-20337 — CVSS 8.2 (high): A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a…
CVE-2026-39394 — CVSS 8.1 (high): CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme…
CVE-2026-40530 — CVSS 8.0 (high): An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before…
CVE-2026-91841 — CVSS 7.8 (high): A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by…
CVE-2026-91840 — CVSS 7.8 (high): A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a…