CWE-93
CVEs classified under CWE-93, newest first.
79 CVEsRSS
GHSA-7cx2-g3h9-382pHigh· 8.1Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
GHSA-268h-hp4c-crq3Medium· 5.4Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
CVE-2026-50269Lowaiohttp: CRLF injection in multipart headers
aiohttp: CRLF injection in multipart headers
CVE-2026-50629Medium· 5.3The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries,…
CVE-2026-28970MediumSwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator
SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator
CVE-2026-12143High· 7.5PoCform-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
CVE-2026-49214Medium· 5.3guzzlehttp/psr7 has CRLF Injection via URI Host Component
guzzlehttp/psr7 has CRLF Injection via URI Host Component
CVE-2026-47240MediumNet::IMAP: Command Injection via non-synchronizing literal in "raw" argument
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-47242MediumNet::IMAP: Command Injection via ID command argument
Net::IMAP: Command Injection via ID command argument
CVE-2026-48596Low· 3.7PoCImproper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2. Tesla.Multipart.add_content_typ…
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2. Tesla.Multipart.add_content_typ…
CVE-2026-42578High· 7.5PoC⚖ disputedNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() …
CVE-2026-43969Low· 3.2Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields. cow_cookie:cookie/1 in cowlib builds a clien…
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields. cow_cookie:cookie/1 in cowlib builds a clien…
CVE-2026-42258Medium· 5.3Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol a…
CVE-2026-1502NoneCR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
CVE-2025-61884High· 7.5CISA KEVPoCVulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI)
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network …
CVE-2025-8419Medium· 5.3A vulnerability was found in Keycloak-services
A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is limited to 64 characters (limited local part of the …
CVE-2023-49082Medium· 5.3aiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker…
CVE-2020-3561Medium· 4.7A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in …
A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in …
CVE-2018-1000164High· 7.5Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers