BaseDraft
CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')
Category: injection
Description
The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.
Common consequences· 1
- Integrity — Modify Application Data
Potential mitigations· 2
- [Implementation]Avoid using CRLF as a special sequence.
- [Implementation]Appropriately filter or quote CRLF sequences in user-controlled input.
Related CAPEC attack patterns· 2
References
Exploits (incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Command Delimiterscapec-15 | 100% | live |
| AttackPattern | Web Server Logs Tamperingcapec-81 | 100% | live |
(incoming)25
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-28357cve-2025-28357 | 0% | live |
| Vulnerability | CVE-2025-59151cve-2025-59151 | 0% | live |
| Vulnerability | Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerabilitycve-2025-61884 | 0% | live |
| Vulnerability | CVE-2025-8715cve-2025-8715 | 0% | live |
| Vulnerability | CVE-2026-1714cve-2026-1714 | 0% | live |
| Vulnerability | CVE-2026-23953cve-2026-23953 | 0% | live |
| Vulnerability | CVE-2026-29046cve-2026-29046 | 0% | live |
| Vulnerability | CVE-2026-32993cve-2026-32993 | 0% | live |
| Vulnerability | CVE-2026-33128cve-2026-33128 | 0% | live |
| Vulnerability | CVE-2026-34458cve-2026-34458 | 0% | live |
| Vulnerability | CVE-2026-35517cve-2026-35517 | 0% | live |
| Vulnerability | CVE-2026-35518cve-2026-35518 | 0% | live |
| Vulnerability | CVE-2026-35519cve-2026-35519 | 0% | live |
| Vulnerability | CVE-2026-35520cve-2026-35520 | 0% | live |
| Vulnerability | CVE-2026-35521cve-2026-35521 | 0% | live |
| Vulnerability | CVE-2026-39394cve-2026-39394 | 0% | live |
| Vulnerability | CVE-2026-39849cve-2026-39849 | 0% | live |
| Vulnerability | CVE-2026-39958cve-2026-39958 | 0% | live |
| Vulnerability | CVE-2026-39983cve-2026-39983 | 0% | live |
| Vulnerability | CVE-2026-41230cve-2026-41230 | 0% | live |
| Vulnerability | CVE-2026-42257cve-2026-42257 | 0% | live |
| Vulnerability | CVE-2026-42258cve-2026-42258 | 0% | live |
| Vulnerability | CVE-2026-46720cve-2026-46720 | 0% | live |
| Vulnerability | CVE-2026-5140cve-2026-5140 | 0% | live |
| KEVEntry | Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerabilitykev-cve-2022-27924 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.