VYPR

CWE-93

Improper Neutralization of CRLF Sequences ('CRLF Injection')

BaseDraft

Description

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-15 · CAPEC-81

CVEs mapped to this weakness (246)

page 3 of 13
  • CVE-2026-35520HigApr 7, 2026
    risk 0.50cvss 8.8epss 0.01

    FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP lease time configuration parameter (dhcp.leaseTime). This…

  • CVE-2026-35519HigApr 7, 2026
    risk 0.50cvss 8.8epss 0.01

    FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS host record configuration parameter (dns.hostRecord). This…

  • CVE-2026-35518HigApr 7, 2026
    risk 0.50cvss 8.8epss 0.01

    FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS CNAME records configuration parameter (dns.cnameRecords).…

  • CVE-2026-35517HigApr 7, 2026
    risk 0.50cvss 8.8epss 0.01

    FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the upstream DNS servers configuration parameter (dns.upstreams).…

  • CVE-2026-93576HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this field, can embed CR/LF characters to…

  • CVE-2026-54511HigAug 26, 2026
    risk 0.49cvss 8.6epss 0.00

    LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F in structured data values, and…

  • CVE-2026-57281HigJun 24, 2026
    risk 0.49cvss 7.5epss 0.01

    Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the…

  • CVE-2026-46741HigJun 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Note that the git repository contains an…

  • CVE-2026-6351HigApr 16, 2026
    risk 0.49cvss 7.5epss 0.01

    MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read system files.

  • CVE-2026-39983HigApr 9, 2026
    risk 0.49cvss 8.6epss 0.02

    basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's…

  • CVE-2026-1714HigFeb 18, 2026
    risk 0.49cvss 8.6epss 0.01

    The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and including, 3.3.2. This is due to the lack of validation on the 'send_to', 'product_title',…

  • CVE-2024-48868HigDec 6, 2024
    risk 0.49cvss 7.5epss 0.00

    An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in…

  • CVE-2024-48867HigDec 6, 2024
    risk 0.49cvss 7.5epss 0.00

    An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in…

  • CVE-2024-1226HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.00

    The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker…

  • CVE-2021-31164HigMay 4, 2021
    risk 0.49cvss 7.5epss 0.02

    Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

  • CVE-2016-10803HigAug 7, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).

  • CVE-2026-50292HigJun 4, 2026
    risk 0.48cvss 7.4epss 0.00

    In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution

  • CVE-2026-41230HigApr 23, 2026
    risk 0.48cvss 8.5epss 0.00

    Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in the `content` field. When a DNS type not covered by the if/elseif validation…

  • CVE-2026-34975HigApr 6, 2026
    risk 0.48cvss 8.5epss 0.00

    Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability was discovered in SESService.ts, where user-supplied values for from.name, subject, custom header keys/values, and attachment filenames were interpolated…

  • CVE-2025-6175HigJul 29, 2025
    risk 0.47cvss 7.2epss 0.00

    Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Splitting. This issue affects Geodi: before GEODI Setup 9.0.146.