CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.
174 vulnerabilities with CWE-93
CVE-2026-42586
MEDIUM
Netty: CRLF Injection in Netty Redis Codec Encoder
CVSS 6.8
CVE-2026-35504
MEDIUM
Subnet Solutions PowerSYSTEM Center CRLF injection
CVSS 5.5
CVE-2026-44217
MEDIUM
sse-channel: SSE Injection via unsanitized event fields
CVE-2026-43882
MEDIUM
WWBN AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing
CVSS 4.3
CVE-2026-43969
LOW
Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CVSS 3.2
CVE-2026-43968
MEDIUM
CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1
CVSS 4.0
CVE-2026-42258
CRITICAL
net-imap: Command Injection via unvalidated Symbol inputs
CVSS 9.8
CVE-2026-42257
CRITICAL
net-imap: Command Injection via "raw" arguments to multiple commands
CVSS 9.8
CVE-2026-41570
HIGH
PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes
CVSS 7.8
CVE-2026-41417
MEDIUM
Netty vulnerable to HTTP request smuggling and RTSP request injection via DefaultHttpRequest.setUri()
CVSS 5.3
CVE-2026-39849
HIGH
Pi-hole FTL remote code execution via newline injection in dns.interface configuration
CVSS 8.8
CVE-2026-34458
HIGH
Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnly
CVSS 8.8
CVE-2026-5140
HIGH
Authorization Bypass in TUBITAK BILGEM's Pardus Update
CVSS 8.8
CVE-2026-42037
MEDIUM
Axios 1.0.0-1.15.0 - Header Injection
CVSS 5.3
CVE-2026-41230
HIGH
Froxlor <2.3.6 DomainZones::add() - BIND Zone File Injection
CVSS 8.5
CVE-2026-2717
MEDIUM
HTTP Headers <= 1.19.2 - Authenticated (Administrator+) CRLF Injection via Custom Header Values
CVSS 5.5
CVE-2026-32964
MEDIUM
silex technology SD-330AC <=Ver.1.42 - CRLF Injection
CVSS 6.5
CVE-2026-6351
HIGH
Openfind|MailGates/MailAudit - CRLF Injection
CVSS 7.5
CVE-2026-2400
MEDIUM
Schneider Electric PowerChute Serial Shutdown <=1.4 - CRLF Injection
CVSS 4.3
CVE-2026-1502
MEDIUM
HTTP client proxy tunnel headers not validated for CR/LF
CVE-2026-35601
MEDIUM
Vikunja <2.3.0 CalDAV Task Output - iCalendar Property Injection
CVSS 4.1
CVE-2026-39983
HIGH
FTP Command Injection via CRLF in basic-ftp
CVSS 8.6
CVE-2026-39958
CRITICAL
oma-topic: name Field in Topic Manifests (topic.json) May Allow CRLF Injection
CVSS 9.1
CVE-2026-39394
HIGH
CI4MS <0.31.4.0 Install Controller host - .env CRLF Injection
CVSS 8.1
CVE-2026-35521
HIGH
Pi-hole FTL affected by Remote Code Execution (RCE) via dhcp.hosts Newline Injection
CVSS 8.8
Details
Vulnerabilities
174