CWE•Base•Draft•20 recent CVEs
CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')
Description
The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.
Common consequences
- Integrity→Modify Application Data
Potential mitigations
- ImplementationAvoid using CRLF as a special sequence.
- ImplementationAppropriately filter or quote CRLF sequences in user-controlled input.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-440929.12026-07-30CVE-2026-151574.22026-07-29CVE-2026-123577.22026-07-29CVE-2026-599206.52026-07-29CVE-2026-599195.52026-07-29CVE-2026-599215.72026-07-28CVE-2026-575115.42026-07-28CVE-2026-163137.62026-07-28CVE-2026-450706.52026-07-14CVE-2026-450672026-07-14CVE-2026-154292026-07-14CVE-2026-501882026-07-09CVE-2026-121275.32026-07-01CVE-2026-572817.52026-06-24CVE-2026-557664.82026-06-23CVE-2026-556037.52026-06-22CVE-2026-472422026-06-22CVE-2026-472402026-06-22CVE-2026-502697.52026-06-22CVE-2026-113739.12026-06-22