VulnSea

CWE-93

CVEs classified under CWE-93, newest first.

71 CVEsRSS

CVE-2026-55159High· 8.8
today

luci-app-adblock-fast: Delegated `luci-app-adblock-fast` users can reach root command execution by injecting newline-separated cron entries

luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carr…

Twilightopenwrt · luci-app-adblock-fastvia CVEORG
CVE-2026-94057Medium· 4.0
2d ago

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

SunlitExim · EximEPSS 0.16%via NVD
CVE-2026-93576High· 7.5
3d ago

A flaw was found in Netty netty-codec-smtp

A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this…

TwilightRed Hat · netty-codec-smtpEPSS 0.27%via NVD
CVE-2026-13666Low· 3.5
3d ago

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to wri…

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to wri…

SunlitSynology · DiskStation Manager (DSM)EPSS 0.19%via NVD
CVE-2026-40530High· 8.0
3d ago

An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arb…

An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arb…

TwilightSynology · DiskStation Manager (DSM)EPSS 0.35%via NVD
CVE-2026-85077High· 8.2
4d ago

Sanic is an opensource python web server/framework

Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 response pipeline in sanic/response/types.py serializes response header names and values without rejecting carriage-return…

Twilightsanic-org · sanicEPSS 0.27%via NVD
CVE-2024-58384Medium· 5.4
6d ago

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitr…

Sunlittornadoweb · tornadoEPSS 0.24%via NVD
CVE-2026-91986Medium· 5.4PoC
6d ago

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof …

TwilightGitoxideLabs · gitoxideEPSS 0.20%via NVD
CVE-2026-90819High· 7.3
1w ago

A weakness has been identified in a2aproject a2a-java 1.2.0

A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificatio…

Twilighta2aproject · a2a-javaEPSS 0.39%via NVD
CVE-2026-90937Critical· 9.9
1w ago

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal new…

Midnightfroxlor · froxlorEPSS 0.26%via NVD
CVE-2026-90767Medium· 6.5PoC
1w ago

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with opti…

Twilightfroxlor · FroxlorEPSS 0.25%via NVD
CVE-2026-86813Medium· 4.8
1w ago

The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, su…

The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, su…

SunlitEPSS 0.15%via NVD
CVE-2026-86252Medium· 5.3PoC
2w ago

h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns

h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type di…

Twilighth3js · h3EPSS 0.22%via NVD
CVE-2026-19862Medium· 4.8
2w ago

The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users…

The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users…

SunlitEPSS 0.15%via NVD
CVE-2026-48019High· 8.9PoC
2w ago

Laravel is a web application framework

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may …

Midnightlaravel · frameworkEPSS 0.68%via NVD
CVE-2026-75925Critical· 9.6
2w ago

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a priv…

MidnightEPSS 0.67%via NVD
CVE-2026-84962Medium· 4.2
2w ago

An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and…

An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and…

Sunlitmongodb · libmongocryptEPSS 0.12%via NVD
CVE-2026-84379Medium· 5.3
2w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-ele…

Sunlithttpx2 · httpx2EPSS 0.26%via NVD
CVE-2026-84372Critical· 9.8
2w ago

Predis is a flexible and feature-complete Redis and Valkey client for PHP

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in Abstr…

Midnightpredis · predis/predisEPSS 0.41%via NVD
CVE-2026-82661Medium· 5.4PoC
3w ago

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF se…

Twilightnodemailer · nodemailerEPSS 0.19%via NVD
CVE-2026-82854Critical· 9.8
3w ago

Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter

Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value…

MidnightEPSS 1.1%via NVD
CVE-2026-82853Medium· 4.9
3w ago

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return a…

SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.73%via NVD
CVE-2026-77341None
3w ago

cpp-httplib is a C++ header-only HTTP/HTTPS library

cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket without validating them, allowing CRLF sequences in a trailer …

SunlitEPSS 0.27%via NVD
CVE-2026-59313Critical· 9.8
3w ago

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Fra…

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Fra…

MidnightEPSS 0.39%via NVD
CVE-2026-54511High· 8.6
3w ago

LogTape is an unobtrusive logging library

LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 thro…

Twilightlogtape · @logtape/syslogEPSS 0.31%via NVD
CVE-2026-77634High
4w ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF…

Twilightcakephp · cakephp/cakephpEPSS 0.31%via NVD
CVE-2026-74866Medium· 5.8
1mo ago

@fastify/busboy is a multipart form-data parser for Node.js

@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-return line-feed sequence, so a lone carriage return or line feed embedded in a part header i…

Sunlitfastify · fastify/busyboyEPSS 0.19%via NVD
GHSA-p77j-g7h5-r2vwHigh
1mo ago

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

Twilightgeolens · geolensvia GHSA
CVE-2026-45125Medium· 5.3
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail header injection. member.php?action=do_emailuser accepts the fromname HTTP parameter for …

SunlitEPSS 0.30%via NVD
CVE-2026-53533Medium
1mo ago

aiosmtplib is an asynchronous SMTP client for use with asyncio

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is…

Sunlitaiosmtplib · aiosmtplibEPSS 0.39%via NVD
CWE-93 vulnerabilities (CVEs) · VulnSea