CWE-93 · 222 records
Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVEs in this class
223 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2021-39172Proof of concept | New line injection during configuration editioncatchethq · catchet · CWE-93 | High8.8 | — | 29.2% | Aug 27, 2021 |
43Plan | CVE-2022-0666Proof of concept | CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microwebermicroweber · microweber · CWE-93 | High7.5 | — | 44.3% | Feb 18, 2022 |
41Plan | CVE-2024-20337No exploit | A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carricisco · secure client · CWE-93 | High8.2 | — | 29.9% | Mar 6, 2024 |
40Plan | CVE-2026-72590No exploit | alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameteralseambusher · crontab-ui · CWE-93 | Critical9.8 | — | 2.0% | Aug 10, 2026 |
40Plan | CVE-2026-77550No exploit | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devicubiquiti inc · unifi os server · CWE-93 | Critical10.0 | — | 0.8% | Aug 26, 2026 |
40Plan | CVE-2026-33128No exploit | h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fieldsh3 · h3 · CWE-93 | Critical10.0 | — | 0.7% | Mar 20, 2026 |
40Plan | CVE-2024-51501No exploit | CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributesreactiveui · refit · CWE-93 | Critical10.0 | — | 0.6% | Nov 4, 2024 |
39Monitor | CVE-2026-84372No exploit | Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionspredis · predis · CWE-93 | Critical9.8 | — | 0.7% | Sep 1, 2026 |
39Monitor | CVE-2026-59313No exploit | Server Sent Event stream corruption in Spring MVC functional web frameworkvmware · spring framework · CWE-93 | Critical9.8 | — | 0.6% | Aug 27, 2026 |
39Monitor | CVE-2026-47890No exploit | Spring Framework Server Sent Event stream corruption while rendering fragmentsvmware · spring framework · CWE-93 | Critical9.8 | — | 0.6% | Aug 27, 2026 |
39Monitor | CVE-2026-50292No exploit | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrfreedesktop · libinput · CWE-93 | Critical9.8 | — | 0.5% | Jun 4, 2026 |
39Monitor | CVE-2026-39394No exploit | CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controllerci4-cms-erp · ci4ms · CWE-93 | Critical9.8 | — | 0.5% | Apr 8, 2026 |
39Monitor | CVE-2026-11362No exploit | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tagsbinary · datadog\ · CWE-93 | Critical9.8 | — | 0.4% | Jun 5, 2026 |
39Monitor | CVE-2026-45372No exploit | cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injectionyhirose · cpp-httplib · CWE-93 | Critical9.9 | — | 0.4% | May 29, 2026 |
38Monitor | CVE-2026-82854No exploit | Nodemailer before 8.0.3 SMTP Command Injection via envelope.sizenodemailer · nodemailer · CWE-93 | Critical9.3 | — | 2.0% | Aug 31, 2026 |
37Monitor | CVE-2026-75925No exploit | IXON VPN Client CRLF Injectionixon · ixon vpn client · CWE-93 | Critical9.4 | — | 0.7% | Sep 4, 2026 |
37Monitor | CVE-2026-90937No exploit | froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URLfroxlor · froxlor · CWE-93 | Critical9.4 | — | 0.5% | Sep 14, 2026 |
37Monitor | CVE-2025-40671No exploit | SQL injection vulnerability in AES Multimedia's Gestnetaes multimedia · gestnet · CWE-93 | Critical9.3 | — | 0.4% | May 26, 2025 |
37Monitor | CVE-2026-34458No exploit | Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnlysandboxie-plus · sandboxie · CWE-93 | Critical9.3 | — | 0.3% | May 5, 2026 |
37Monitor | CVE-2026-82973No exploit | Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailboxpsyb0t · docker-mailbox · CWE-93 | Critical9.4 | — | — | 1 day ago |
36Monitor | CVE-2016-3115Proof of concept | Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended sheopenbsd · openssh · CWE-93 | Medium6.4 | — | 37.0% | Mar 22, 2016 |
36Monitor | CVE-2026-11373No exploit | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injectionsjasei · net::statsite::client · CWE-93 | Critical9.1 | — | 0.6% | Jun 22, 2026 |
36Monitor | CVE-2026-50638No exploit | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injectionspevans · metrics\ · CWE-93 | Critical9.1 | — | 0.6% | Jun 10, 2026 |
36Monitor | CVE-2026-9270No exploit | DataDog::DogStatsd versions through 0.07 for Perl allow metric injectionsbinary · datadog\ · CWE-93 | Critical9.1 | — | 0.5% | Jun 5, 2026 |
36Monitor | CVE-2026-77549No exploit | A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulneraubiquiti inc · unifi os server · CWE-93 | Critical9.0 | — | 0.5% | Aug 26, 2026 |
- CVE-2021-3917244Plan
New line injection during configuration edition
HighCVSS 8.8Proof of conceptEPSS 29%catchethq · catchetAug 27, 2021
- CVE-2022-066643Plan
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
HighCVSS 7.5Proof of conceptEPSS 44%microweber · microweberFeb 18, 2022
- CVE-2024-2033741Plan
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carri
HighCVSS 8.2No exploitEPSS 30%cisco · secure clientMar 6, 2024
- CVE-2026-7259040Plan
alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter
CriticalCVSS 9.8No exploitEPSS 2%alseambusher · crontab-uiAug 10, 2026
- CVE-2026-7755040Plan
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devic
CriticalCVSS 10.0No exploitEPSS 1%ubiquiti inc · unifi os serverAug 26, 2026
- CVE-2026-3312840Plan
h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields
CriticalCVSS 10.0No exploitEPSS 1%h3 · h3Mar 20, 2026
- CVE-2024-5150140Plan
CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes
CriticalCVSS 10.0No exploitEPSS 1%reactiveui · refitNov 4, 2024
- CVE-2026-8437239Monitor
Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
CriticalCVSS 9.8No exploitEPSS 1%predis · predisSep 1, 2026
- CVE-2026-5931339Monitor
Server Sent Event stream corruption in Spring MVC functional web framework
CriticalCVSS 9.8No exploitEPSS 1%vmware · spring frameworkAug 27, 2026
- CVE-2026-4789039Monitor
Spring Framework Server Sent Event stream corruption while rendering fragments
CriticalCVSS 9.8No exploitEPSS 1%vmware · spring frameworkAug 27, 2026
- CVE-2026-5029239Monitor
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitr
CriticalCVSS 9.8No exploitEPSS 1%freedesktop · libinputJun 4, 2026
- CVE-2026-3939439Monitor
CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
CriticalCVSS 9.8No exploitEPSS 1%ci4-cms-erp · ci4msApr 8, 2026
- CVE-2026-1136239Monitor
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags
CriticalCVSS 9.8No exploitEPSS 0%binary · datadog\Jun 5, 2026
- CVE-2026-4537239Monitor
cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection
CriticalCVSS 9.9No exploitEPSS 0%yhirose · cpp-httplibMay 29, 2026
- CVE-2026-8285438Monitor
Nodemailer before 8.0.3 SMTP Command Injection via envelope.size
CriticalCVSS 9.3No exploitEPSS 2%nodemailer · nodemailerAug 31, 2026
- CVE-2026-7592537Monitor
IXON VPN Client CRLF Injection
CriticalCVSS 9.4No exploitEPSS 1%ixon · ixon vpn clientSep 4, 2026
- CVE-2026-9093737Monitor
froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL
CriticalCVSS 9.4No exploitEPSS 0%froxlor · froxlorSep 14, 2026
- CVE-2025-4067137Monitor
SQL injection vulnerability in AES Multimedia's Gestnet
CriticalCVSS 9.3No exploitEPSS 0%aes multimedia · gestnetMay 26, 2025
- CVE-2026-3445837Monitor
Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnly
CriticalCVSS 9.3No exploitEPSS 0%sandboxie-plus · sandboxieMay 5, 2026
- CVE-2026-8297337Monitor
Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox
CriticalCVSS 9.4No exploitpsyb0t · docker-mailbox1 day ago
- CVE-2016-311536Monitor
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended she
MediumCVSS 6.4Proof of conceptEPSS 37%openbsd · opensshMar 22, 2016
- CVE-2026-1137336Monitor
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
CriticalCVSS 9.1No exploitEPSS 1%jasei · net::statsite::clientJun 22, 2026
- CVE-2026-5063836Monitor
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections
CriticalCVSS 9.1No exploitEPSS 1%pevans · metrics\Jun 10, 2026
- CVE-2026-927036Monitor
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
CriticalCVSS 9.1No exploitEPSS 1%binary · datadog\Jun 5, 2026
- CVE-2026-7754936Monitor
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnera
CriticalCVSS 9.0No exploitEPSS 1%ubiquiti inc · unifi os serverAug 26, 2026