Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final
PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sani
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacke
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inje
The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing H
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o
lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-ve
RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header valu
A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) charac
A security vulnerability has been detected in Ritlabs TinyWeb Server 1.94. This vulnerability affects unknown code of th
Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to ht
A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for
Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit attributes
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF inje
Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is
Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library do
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerabilit
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerabilit
AMI SPx contains a vulnerability in the BMC where an Attacker may cause an improper neutralization of CRLF sequences in
All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to
All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set requ
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible fo
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist micro
Nextcloud server is an open source personal cloud server. Affected versions were found to be vulnerable to SMTP command
undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request hea
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection
Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
phpservermon is vulnerable to Improper Neutralization of CRLF Sequences
In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could cha
A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepow
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to perform a carriag
In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection
cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).
Incorrect implementation in Content Security Policy in Google Chrome prior to 67.0.3396.79 allowed a remote attacker to
www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout vi
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection i
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, a
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection i
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parame
An issue was discovered in Weaver e-cology 9.0. There is a CRLF Injection vulnerability via the /workflow/request/ViewRe
An issue was discovered in the hyper crate before 0.9.18 for Rust. It mishandles newlines in headers.
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to e
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigat
Frequently Asked Questions
What is CWE-93?
CWE-93 (CWE-93) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-93?
There are 224 CVE records associated with CWE-93 in our database. Of these, 15 are critical severity, 59 are high severity, and 106 are medium severity.
How can I protect against CWE-93 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-93 using AI-powered security agents.
Detect CWE-93 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-93 vulnerabilities across your infrastructure.
Get Started