VulnSea

CWE-93

CVEs classified under CWE-93, newest first.

71 CVEsRSS

CVE-2026-53788Medium· 6.5
1mo ago

rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters

rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters. Attackers…

SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.27%via NVD
CVE-2026-16455None
1mo ago

In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due t…

In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due t…

SunlitEPSS 0.20%via NVD
CVE-2026-72913High· 7.8
1mo ago

Kitty is a cross-platform GPU based terminal

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.27%via NVD
CVE-2026-72590Critical· 9.8
1mo ago

An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /crontab with URL-encoded newlines in the e…

An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /crontab with URL-encoded newlines in the e…

MidnightEPSS 1.3%via NVD
CVE-2026-71311Medium· 6.4
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately before an…

Sunlitrclone · github.com/rclone/rcloneEPSS 0.24%via NVD
CVE-2026-15157Medium· 4.2
1mo ago

undici vulnerable to CRLF Injection via blob-like body 'type' property

undici vulnerable to CRLF Injection via blob-like body 'type' property

Sunlitundici · undiciEPSS 0.19%via GHSA
CVE-2026-67326High· 7.0
1mo ago

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] se…

Twilightgitpython_project · gitpythonEPSS 0.28%via NVD
CVE-2026-49756Medium
1mo ago

Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type

Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type

Sunlitreq · reqEPSS 0.21%via GHSA
CVE-2026-16313High· 7.6
1mo ago

A flaw was found in sg3_utils

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-suppl…

TwilightRed Hat · sg3_utilsEPSS 0.29%via NVD
CVE-2026-59919Medium· 5.5
2mo ago

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

Sunlitnetty · io.netty:netty-codec-haproxyEPSS 0.14%via GHSA
CVE-2026-59920Medium· 6.5
2mo ago

Netty: STOMP CONNECT Frame Header Injection in Netty

Netty: STOMP CONNECT Frame Header Injection in Netty

Sunlitnetty · io.netty:netty-codec-stompEPSS 0.24%via GHSA
CVE-2026-59921Medium· 5.7
2mo ago

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

Sunlitnetty · io.netty:netty-codec-httpEPSS 0.25%via GHSA
CVE-2026-48596Low
2mo ago

Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`

Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`

Sunlittesla · teslaEPSS 0.24%via GHSA
CVE-2026-48861Low
2mo ago

mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`

mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`

Sunlitmint · mintEPSS 0.17%via GHSA
CVE-2026-47069Low
2mo ago

Hackney has CRLF / header injection via unvalidated `domain` and `path` options

Hackney has CRLF / header injection via unvalidated `domain` and `path` options

Sunlithackney · hackneyEPSS 0.43%via GHSA
CVE-2026-47075Medium
2mo ago

Hackney has CR/LF injection in query parameter

Hackney has CR/LF injection in query parameter

Sunlithackney · hackneyEPSS 0.48%via GHSA
CVE-2026-47072Medium
2mo ago

Hackney has CRLF / header injection in WebSocket upgrade request

Hackney has CRLF / header injection in WebSocket upgrade request

Sunlithackney · hackneyEPSS 0.54%via GHSA
GHSA-74p7-6h78-gw8pHigh
3mo ago

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

Twilightskillctl · skillctlvia GHSA
CVE-2026-9679Medium· 5.9
3mo ago

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

Sunlitundici · undiciEPSS 0.26%via GHSA
CVE-2026-55766Medium· 4.8
3mo ago

guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization

guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization

Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.23%via GHSA
CVE-2026-55603High· 7.5
3mo ago

http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`

http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`

Twilighthttp-proxy-middleware · http-proxy-middlewareEPSS 0.29%via GHSA
CVE-2026-50188Medium
3mo ago

Kirby: Request header injection in `Http\Remote`

Kirby: Request header injection in `Http\Remote`

Sunlitgetkirby · getkirby/cmsEPSS 0.44%via GHSA
GHSA-5vg9-5847-vvmqHigh· 8.9
3mo ago

Laravel Framework: CRLF injection in default email rule

Laravel Framework: CRLF injection in default email rule

Twilightlaravel · laravel/frameworkvia GHSA
GHSA-7cx2-g3h9-382pHigh· 8.1
3mo ago

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

Twilightcrawl4ai · crawl4aivia GHSA
GHSA-268h-hp4c-crq3Medium· 5.4
3mo ago

Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

Sunlitnodemailer · nodemailervia GHSA
CVE-2026-50269Low
3mo ago

aiohttp: CRLF injection in multipart headers

aiohttp: CRLF injection in multipart headers

Sunlitaiohttp · aiohttpEPSS 0.30%via OSV
CVE-2026-50629Medium· 5.3
3mo ago

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries,…

Sunlitapache · cxfEPSS 0.42%via NVD
CVE-2026-28970Medium
3mo ago

SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator

SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator

Sunlitapple · github.com/apple/swift-niovia GHSA
CVE-2026-12143High· 7.5PoC
3mo ago

form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…

Midnightform-data · form-dataEPSS 0.53%via CVEORG
CVE-2026-49214Medium· 5.3
3mo ago

guzzlehttp/psr7 has CRLF Injection via URI Host Component

guzzlehttp/psr7 has CRLF Injection via URI Host Component

Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.19%via GHSA
CWE-93 vulnerabilities (CVEs) — page 2 · VulnSea