Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splittin
A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request split
An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline
When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not b
User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL
When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messa
The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when seria
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
sse-channel is an SSE-implementation which can be used to any node.js http request/response stream. Prior to 4.0.1, impl
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allows HTTP Request Split
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, wh
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Htt
### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply
Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inj
Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/wind
In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 throu
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of out
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementat
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), a
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated r
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their res
cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes
Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code
A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supp
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker bloc
Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sen
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Sp
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o
CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows
Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insuffi
CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding addi
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final
A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improp
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o
An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that c
CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject a
A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Inje
An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3,
A vulnerability was found in code-projects Rental Management System 2.0. This affects an unknown function of the file Tr
SQL injection vulnerability in AES Multimedia's Gestnet v1.07. This vulnerability allows an attacker to retrieve, create
HTTP.jl provides HTTP client and server functionality for Julia, and URIs.jl parses and works with Uniform Resource Iden
ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In version
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/2 request splitting vulne
Frequently Asked Questions
What is CWE-93?
CWE-93 (CWE-93) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-93?
There are 224 CVE records associated with CWE-93 in our database. Of these, 15 are critical severity, 59 are high severity, and 106 are medium severity.
How can I protect against CWE-93 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-93 using AI-powered security agents.
Detect CWE-93 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-93 vulnerabilities across your infrastructure.
Get Started