Skip to content
Noroxi

CWE-93 · 222 records

Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVEs in this class

223 records

  • New line injection during configuration edition

    HighCVSS 8.8Proof of conceptEPSS 29%

    catchethq · catchetAug 27, 2021

  • CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber

    HighCVSS 7.5Proof of conceptEPSS 44%

    microweber · microweberFeb 18, 2022

  • A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carri

    HighCVSS 8.2No exploitEPSS 30%

    cisco · secure clientMar 6, 2024

  • alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter

    CriticalCVSS 9.8No exploitEPSS 2%

    alseambusher · crontab-uiAug 10, 2026

  • A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devic

    CriticalCVSS 10.0No exploitEPSS 1%

    ubiquiti inc · unifi os serverAug 26, 2026

  • h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields

    CriticalCVSS 10.0No exploitEPSS 1%

    h3 · h3Mar 20, 2026

  • CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes

    CriticalCVSS 10.0No exploitEPSS 1%

    reactiveui · refitNov 4, 2024

  • Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections

    CriticalCVSS 9.8No exploitEPSS 1%

    predis · predisSep 1, 2026

  • Server Sent Event stream corruption in Spring MVC functional web framework

    CriticalCVSS 9.8No exploitEPSS 1%

    vmware · spring frameworkAug 27, 2026

  • Spring Framework Server Sent Event stream corruption while rendering fragments

    CriticalCVSS 9.8No exploitEPSS 1%

    vmware · spring frameworkAug 27, 2026

  • In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitr

    CriticalCVSS 9.8No exploitEPSS 1%

    freedesktop · libinputJun 4, 2026

  • CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controller

    CriticalCVSS 9.8No exploitEPSS 1%

    ci4-cms-erp · ci4msApr 8, 2026

  • DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags

    CriticalCVSS 9.8No exploitEPSS 0%

    binary · datadog\Jun 5, 2026

  • cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection

    CriticalCVSS 9.9No exploitEPSS 0%

    yhirose · cpp-httplibMay 29, 2026

  • Nodemailer before 8.0.3 SMTP Command Injection via envelope.size

    CriticalCVSS 9.3No exploitEPSS 2%

    nodemailer · nodemailerAug 31, 2026

  • IXON VPN Client CRLF Injection

    CriticalCVSS 9.4No exploitEPSS 1%

    ixon · ixon vpn clientSep 4, 2026

  • froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL

    CriticalCVSS 9.4No exploitEPSS 0%

    froxlor · froxlorSep 14, 2026

  • SQL injection vulnerability in AES Multimedia's Gestnet

    CriticalCVSS 9.3No exploitEPSS 0%

    aes multimedia · gestnetMay 26, 2025

  • Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnly

    CriticalCVSS 9.3No exploitEPSS 0%

    sandboxie-plus · sandboxieMay 5, 2026

  • Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox

    CriticalCVSS 9.4No exploit

    psyb0t · docker-mailbox1 day ago

  • CVE-2016-3115
    36Monitor

    Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended she

    MediumCVSS 6.4Proof of conceptEPSS 37%

    openbsd · opensshMar 22, 2016

  • Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections

    CriticalCVSS 9.1No exploitEPSS 1%

    jasei · net::statsite::clientJun 22, 2026

  • Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections

    CriticalCVSS 9.1No exploitEPSS 1%

    pevans · metrics\Jun 10, 2026

  • CVE-2026-9270
    36Monitor

    DataDog::DogStatsd versions through 0.07 for Perl allow metric injections

    CriticalCVSS 9.1No exploitEPSS 1%

    binary · datadog\Jun 5, 2026

  • A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnera

    CriticalCVSS 9.0No exploitEPSS 1%

    ubiquiti inc · unifi os serverAug 26, 2026

All vulnerability classes