Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-93

Improper Neutralization of CRLF Sequences ('CRLF Injection')

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

188
Assigned CVEs
129th
Commonality Rank
6.5
Avg CVSS
0.5%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-93 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2007
19 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

188 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-61884HIGH
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vu
Oct 12, 20257.598YESYES
CVE-2016-3115MEDIUM
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11
Mar 22, 20166.453NOYES
CVE-2022-0666HIGH
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11.
Feb 18, 20227.552NOYES
CVE-2019-10678HIGH
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
Mar 31, 20197.544NOYES
CVE-2021-39172HIGH
Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the co
Aug 27, 20218.843NONO
CVE-2026-50292CRITICAL
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
Jun 4, 20269.841NONO
CVE-2016-4975MEDIUM
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or
Aug 14, 20186.141NOYES
CVE-2026-45372CRITICAL
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding
May 29, 20269.940NONO
CVE-2018-19585HIGH
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.
May 17, 20197.540NOYES
CVE-2026-42257CRITICAL
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw stri
May 9, 20269.837NONO
View all 188 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
9%
10%
4.0-4.9
23%
19%
5.0-5.9
27%
16%
6.0-6.9
17%
26%
7.0-7.9
14%
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
0.5% of CVEs· 85th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
2.7% of CVEs· 91st percentile
ExploitDB
4 CVEs
2.1% of CVEs· 88th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products