CWE-93Base1 in KEV

Improper Neutralization of CRLF Sequences ('CRLF Injection')

Draft in the CWE catalog · 190 CVEs mapped

190
CVEs mapped
1
In KEV
6.5
Median CVSS
What it is

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Recent examples
4.8cvss
CVE-2026-19862

CVE-2026-19862 - MEDIUM Severity Vulnerability

The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field.

MEDIUMno explanation yet
epss
8.9cvss
CVE-2026-48019

CVE-2026-48019 - HIGH Severity Vulnerability

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in applications that send mail to user-supplied addresses. This issue has been patched in versions 12.60.0 and 13.10.0.

HIGHno explanation yet
1%
epss
9.6cvss
CVE-2026-75925

CVE-2026-75925 - CRITICAL Severity Vulnerability

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester. The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user.

CRITICALno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-93
Abstraction
Base
Structure
Simple
Status
Draft
References (3)