CWE-93
CVEs classified under CWE-93, newest first.
71 CVEsRSS
CVE-2026-53788Medium· 6.5rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters
rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters. Attackers…
CVE-2026-16455NoneIn Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due t…
In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due t…
CVE-2026-72913High· 7.8Kitty is a cross-platform GPU based terminal
Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command…
CVE-2026-72590Critical· 9.8An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /crontab with URL-encoded newlines in the e…
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /crontab with URL-encoded newlines in the e…
CVE-2026-71311Medium· 6.4rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately before an…
CVE-2026-15157Medium· 4.2undici vulnerable to CRLF Injection via blob-like body 'type' property
undici vulnerable to CRLF Injection via blob-like body 'type' property
CVE-2026-67326High· 7.0GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config
GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] se…
CVE-2026-49756MediumReq vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
CVE-2026-16313High· 7.6A flaw was found in sg3_utils
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-suppl…
CVE-2026-59919Medium· 5.5Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
CVE-2026-59920Medium· 6.5Netty: STOMP CONNECT Frame Header Injection in Netty
Netty: STOMP CONNECT Frame Header Injection in Netty
CVE-2026-59921Medium· 5.7Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
CVE-2026-48596LowTesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
CVE-2026-48861Lowmint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
CVE-2026-47069LowHackney has CRLF / header injection via unvalidated `domain` and `path` options
Hackney has CRLF / header injection via unvalidated `domain` and `path` options
CVE-2026-47075MediumHackney has CR/LF injection in query parameter
Hackney has CR/LF injection in query parameter
CVE-2026-47072MediumHackney has CRLF / header injection in WebSocket upgrade request
Hackney has CRLF / header injection in WebSocket upgrade request
GHSA-74p7-6h78-gw8pHighskillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
CVE-2026-9679Medium· 5.9undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
CVE-2026-55766Medium· 4.8guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
CVE-2026-55603High· 7.5http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
CVE-2026-50188MediumKirby: Request header injection in `Http\Remote`
Kirby: Request header injection in `Http\Remote`
GHSA-5vg9-5847-vvmqHigh· 8.9Laravel Framework: CRLF injection in default email rule
Laravel Framework: CRLF injection in default email rule
GHSA-7cx2-g3h9-382pHigh· 8.1Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
GHSA-268h-hp4c-crq3Medium· 5.4Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
CVE-2026-50269Lowaiohttp: CRLF injection in multipart headers
aiohttp: CRLF injection in multipart headers
CVE-2026-50629Medium· 5.3The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries,…
CVE-2026-28970MediumSwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator
SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator
CVE-2026-12143High· 7.5PoCform-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
CVE-2026-49214Medium· 5.3guzzlehttp/psr7 has CRLF Injection via URI Host Component
guzzlehttp/psr7 has CRLF Injection via URI Host Component