CWE-93
AllowedImproper Neutralization of CRLF Sequences ('CRLF Injection')
Abstraction: Base · Status: Draft
The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.
433 vulnerabilities reference this CWE, most recent first.
GHSA-99X9-VRRC-XXW3
Vulnerability from github – Published: 2024-05-31 18:31 – Updated: 2025-03-27 21:31A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.
{
"affected": [],
"aliases": [
"CVE-2023-38551"
],
"database_specific": {
"cwe_ids": [
"CWE-93"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-31T18:15:09Z",
"severity": "HIGH"
},
"details": "A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim\u2019s browser, thereby leading to cross-site scripting attack.",
"id": "GHSA-99x9-vrrc-xxw3",
"modified": "2025-03-27T21:31:15Z",
"published": "2024-05-31T18:31:16Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38551"
},
{
"type": "WEB",
"url": "https://forums.ivanti.com/s/article/Security-Advisory-May-2024"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-9CX9-X2GP-9QVH
Vulnerability from github – Published: 2021-06-29 21:24 – Updated: 2023-02-09 17:46Impact
The filename that is given in c.Attachment() is not escaped, and therefore vulnerable for a CRLF injection attack. I.e. an attacker could upload a custom filename and then give the link to the victim. With this filename, the attacker can change the name of the downloaded file, redirect to another site, change the authorization header, etc.
Steps to reproduce
package main
import "github.com/gofiber/fiber"
const badFileName = "another secret document.pdf\"\r\nLocation: google.com\r\nAuthorization: \"example_of_session_fixation"
func splitTheResponse(c *fiber.Ctx) {
c.Attachment(badFileName)
}
func main() {
app := fiber.New()
app.Get("/attack", splitTheResponse)
app.Listen("127.0.0.1:8080")
}
HTTP/1.1 200 OK
Date: Fri, 10 Jul 2020 19:47:04 GMT
Content-Type: application/octet-stream
Content-Length: 0
Content-Disposition: attachment; filename="another secret document.pdf"
Location: google.com
Authorization: "example_of_session_fixation"
Patches
This issue has been patched in v1.12.6 with commit 579 escaping the filename by default.
Workarounds
You could of course serialize the input yourself before passing it to ctx.Attachment(), this is actually a good practice by default. But in case you forget, we got you covered 👍
References
A CRLF injection attack is one of several types of injection attacks. It can be used to escalate to more malicious attacks such as Cross-site Scripting (XSS), page injection, web cache poisoning, cache-based defacement, and more. A CRLF injection vulnerability exists if an attacker can inject the CRLF characters into a web application, for example using a user input form or an HTTP request, see acunetix
For more information
If you have any questions or comments about this advisory: * Open an issue in gofiber/fiber * Join us on Discord
{
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/gofiber/fiber"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.12.6"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2020-15111"
],
"database_specific": {
"cwe_ids": [
"CWE-74",
"CWE-93"
],
"github_reviewed": true,
"github_reviewed_at": "2021-05-24T19:14:18Z",
"nvd_published_at": "2020-07-20T18:15:00Z",
"severity": "MODERATE"
},
"details": "### Impact\nThe filename that is given in [c.Attachment()](https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore vulnerable for a CRLF injection attack. I.e. an attacker could upload a custom filename and then give the link to the victim. With this filename, the attacker can change the name of the downloaded file, redirect to another site, change the authorization header, etc.\n\n### Steps to reproduce\n```go\npackage main\n\nimport \"github.com/gofiber/fiber\"\n\nconst badFileName = \"another secret document.pdf\\\"\\r\\nLocation: google.com\\r\\nAuthorization: \\\"example_of_session_fixation\"\n\nfunc splitTheResponse(c *fiber.Ctx) {\n\tc.Attachment(badFileName)\n}\n\nfunc main() {\n\tapp := fiber.New()\n\tapp.Get(\"/attack\", splitTheResponse)\n\tapp.Listen(\"127.0.0.1:8080\")\n}\n```\n```\nHTTP/1.1 200 OK\nDate: Fri, 10 Jul 2020 19:47:04 GMT\nContent-Type: application/octet-stream\nContent-Length: 0\nContent-Disposition: attachment; filename=\"another secret document.pdf\"\nLocation: google.com\nAuthorization: \"example_of_session_fixation\"\n```\n\n### Patches\nThis issue has been patched in `v1.12.6` with commit [579](https://github.com/gofiber/fiber/pull/579/commits/f698b5d5066cfe594102ae252cd58a1fe57cf56f) escaping the filename by default.\n\n### Workarounds\nYou could of course serialize the input yourself before passing it to `ctx.Attachment()`, this is actually a good practice by default. But in case you forget, we got you covered \ud83d\udc4d \n\n### References\nA CRLF injection attack is one of several types of injection attacks. It can be used to escalate to more malicious attacks such as Cross-site Scripting (XSS), page injection, web cache poisoning, cache-based defacement, and more. A CRLF injection vulnerability exists if an attacker can inject the CRLF characters into a web application, for example using a user input form or an HTTP request, [see acunetix](https://www.acunetix.com/websitesecurity/crlf-injection/)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [gofiber/fiber](https://github.com/gofiber/fiber)\n* Join us on [Discord](https://gofiber.io/discord)",
"id": "GHSA-9cx9-x2gp-9qvh",
"modified": "2023-02-09T17:46:27Z",
"published": "2021-06-29T21:24:28Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/gofiber/fiber/security/advisories/GHSA-9cx9-x2gp-9qvh"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-15111"
},
{
"type": "WEB",
"url": "https://github.com/gofiber/fiber/pull/579"
},
{
"type": "WEB",
"url": "https://github.com/gofiber/fiber/commit/f698b5d5066cfe594102ae252cd58a1fe57cf56f"
},
{
"type": "PACKAGE",
"url": "https://github.com/gofiber/fiber"
},
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2021-0108"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N",
"type": "CVSS_V3"
}
],
"summary": "CRLF vulnerability in Fiber"
}
GHSA-9H9J-4VRJ-GF7G
Vulnerability from github – Published: 2026-09-30 23:53 – Updated: 2026-09-30 23:53Summary
pyvenv.cfg is a line-based format with no escape syntax. PyEnvCfg.write() wrote values verbatim, while PyEnvCfg._read_values() parses the file with str.splitlines(). A value containing a line boundary therefore became additional configuration lines, and because reading is last-wins, the injected keys replaced any key written earlier in the file.
Impact
The prompt value is the reachable input: it is set by --prompt, by the VIRTUALENV_PROMPT environment variable, or from the config file, and write() emits prompt before home. A crafted prompt can therefore set home in the generated pyvenv.cfg:
$ virtualenv --prompt $'x"\nhome = /attacker/path\nprompt = "z' venv
$ grep '^home' venv/pyvenv.cfg
home = /attacker/path
home is what tooling reads to locate the base interpreter, so a consumer that trusts it can be pointed elsewhere. implementation, version_info, version, executable, command and virtualenv are also written before prompt and can be replaced the same way.
This requires the prompt to come from somewhere other than the person running the command, for example a CI job templating a branch name into it, tooling deriving an environment name from user-supplied data, or an inherited VIRTUALENV_PROMPT. Where the operator supplies the prompt directly they already control the command line, and the effect is corruption rather than privilege gain: the value is truncated at the boundary and read back with a dangling quote.
Details
The boundary set is the one str.splitlines() recognizes, which is wider than \n: \r, \v, \f, the file, group and record separators, U+0085, U+2028 and U+2029 were all written through unchanged and all split the line when read back.
Patches
PyEnvCfg.write() now collapses those boundaries to spaces as it serializes each line, so it cannot emit a structurally invalid file regardless of what a caller places in content.
Workarounds
Do not pass externally influenced data as the virtualenv prompt. Strip line boundaries from any value before using it as --prompt or VIRTUALENV_PROMPT.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 21.7.10"
},
"package": {
"ecosystem": "PyPI",
"name": "virtualenv"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "21.7.11"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-102938"
],
"database_specific": {
"cwe_ids": [
"CWE-93"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-30T23:53:58Z",
"nvd_published_at": "2026-09-29T21:17:19Z",
"severity": "MODERATE"
},
"details": "### Summary\n\n`pyvenv.cfg` is a line-based format with no escape syntax. `PyEnvCfg.write()` wrote values verbatim, while `PyEnvCfg._read_values()` parses the file with `str.splitlines()`. A value containing a line boundary therefore became additional configuration lines, and because reading is last-wins, the injected keys replaced any key written earlier in the file.\n\n### Impact\n\nThe `prompt` value is the reachable input: it is set by `--prompt`, by the `VIRTUALENV_PROMPT` environment variable, or from the config file, and `write()` emits `prompt` before `home`. A crafted prompt can therefore set `home` in the generated `pyvenv.cfg`:\n\n```console\n$ virtualenv --prompt $\u0027x\"\\nhome = /attacker/path\\nprompt = \"z\u0027 venv\n$ grep \u0027^home\u0027 venv/pyvenv.cfg\nhome = /attacker/path\n```\n\n`home` is what tooling reads to locate the base interpreter, so a consumer that trusts it can be pointed elsewhere. `implementation`, `version_info`, `version`, `executable`, `command` and `virtualenv` are also written before `prompt` and can be replaced the same way.\n\nThis requires the prompt to come from somewhere other than the person running the command, for example a CI job templating a branch name into it, tooling deriving an environment name from user-supplied data, or an inherited `VIRTUALENV_PROMPT`. Where the operator supplies the prompt directly they already control the command line, and the effect is corruption rather than privilege gain: the value is truncated at the boundary and read back with a dangling quote.\n\n### Details\n\nThe boundary set is the one `str.splitlines()` recognizes, which is wider than `\\n`: `\\r`, `\\v`, `\\f`, the file, group and record separators, `U+0085`, `U+2028` and `U+2029` were all written through unchanged and all split the line when read back.\n\n### Patches\n\n`PyEnvCfg.write()` now collapses those boundaries to spaces as it serializes each line, so it cannot emit a structurally invalid file regardless of what a caller places in `content`.\n\n### Workarounds\n\nDo not pass externally influenced data as the virtualenv prompt. Strip line boundaries from any value before using it as `--prompt` or `VIRTUALENV_PROMPT`.",
"id": "GHSA-9h9j-4vrj-gf7g",
"modified": "2026-09-30T23:53:58Z",
"published": "2026-09-30T23:53:58Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/pypa/virtualenv/security/advisories/GHSA-9h9j-4vrj-gf7g"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102938"
},
{
"type": "WEB",
"url": "https://github.com/pypa/virtualenv/pull/3247"
},
{
"type": "WEB",
"url": "https://github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4012.yaml"
},
{
"type": "PACKAGE",
"url": "https://github.com/pypa/virtualenv"
},
{
"type": "WEB",
"url": "https://github.com/pypa/virtualenv/releases/tag/21.7.11"
},
{
"type": "WEB",
"url": "https://pypi.org/project/virtualenv"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection"
}
GHSA-9JXW-CFRH-JXQ6
Vulnerability from github – Published: 2021-08-30 16:11 – Updated: 2022-08-11 00:16Impact
Authenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server.
Patches
This issue was addressed by improving UpdateConfigCommandHandler and preventing the use of new lines characters in new configuration values.
Workarounds
Only allow trusted source IP addresses to access to the administration dashboard.
References
- https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection
For more information
If you have any questions or comments about this advisory, you can contact: - The original reporters, by sending an email to vulnerability.research [at] sonarsource.com; - The maintainers, by opening an issue on this repository.
{
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "cachethq/cachet"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.5.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2021-39172"
],
"database_specific": {
"cwe_ids": [
"CWE-93"
],
"github_reviewed": true,
"github_reviewed_at": "2021-08-27T23:35:16Z",
"nvd_published_at": "2021-08-27T23:15:00Z",
"severity": "HIGH"
},
"details": "### Impact\n\nAuthenticated users, regardless of their privileges (_User_ or _Admin_), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server.\n\n### Patches\n\nThis issue was addressed by improving `UpdateConfigCommandHandler` and preventing the use of new lines characters in new configuration values.\n\n### Workarounds\n\nOnly allow trusted source IP addresses to access to the administration dashboard.\n\n### References\n\n- https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection\n\n### For more information\n\nIf you have any questions or comments about this advisory, you can contact:\n- The original reporters, by sending an email to vulnerability.research [at] sonarsource.com;\n- The maintainers, by opening an issue on this repository.\n",
"id": "GHSA-9jxw-cfrh-jxq6",
"modified": "2022-08-11T00:16:20Z",
"published": "2021-08-30T16:11:24Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/fiveai/Cachet/security/advisories/GHSA-9jxw-cfrh-jxq6"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39172"
},
{
"type": "WEB",
"url": "https://github.com/fiveai/Cachet/commit/6442976c25930cb370c65a22784b9caee7ed1de2"
},
{
"type": "WEB",
"url": "https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection"
},
{
"type": "PACKAGE",
"url": "https://github.com/fiveai/Cachet"
},
{
"type": "WEB",
"url": "https://github.com/fiveai/Cachet/releases/tag/v2.5.1"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Cachet vulnerable to new line injection during configuration edition"
}
GHSA-9MMM-R5XW-7773
Vulnerability from github – Published: 2026-05-12 21:31 – Updated: 2026-05-12 21:31PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.
{
"affected": [],
"aliases": [
"CVE-2026-35504"
],
"database_specific": {
"cwe_ids": [
"CWE-93"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-05-12T21:16:15Z",
"severity": "MODERATE"
},
"details": "PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.",
"id": "GHSA-9mmm-r5xw-7773",
"modified": "2026-05-12T21:31:36Z",
"published": "2026-05-12T21:31:36Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35504"
},
{
"type": "WEB",
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-132-02.json"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-02"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-9QRJ-JM5V-82P9
Vulnerability from github – Published: 2026-09-06 12:30 – Updated: 2026-09-06 12:30The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field.
{
"affected": [],
"aliases": [
"CVE-2026-19862"
],
"database_specific": {
"cwe_ids": [
"CWE-93"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-06T10:17:14Z",
"severity": "MODERATE"
},
"details": "The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message\u0027s addresses from a form field.",
"id": "GHSA-9qrj-jm5v-82p9",
"modified": "2026-09-06T12:30:23Z",
"published": "2026-09-06T12:30:23Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19862"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/b3fe5552-6736-4479-9c61-c05bc3328b8e"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-9RPW-6GHH-QX6Q
Vulnerability from github – Published: 2024-03-12 15:32 – Updated: 2024-03-12 15:32The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker could control the response and craft attacks such as cross-site scripting and cache poisoning attacks.
{
"affected": [],
"aliases": [
"CVE-2024-1226"
],
"database_specific": {
"cwe_ids": [
"CWE-93"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-12T15:15:47Z",
"severity": "HIGH"
},
"details": "The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker could control the response and craft attacks such as cross-site scripting and cache poisoning attacks.",
"id": "GHSA-9rpw-6ghh-qx6q",
"modified": "2024-03-12T15:32:21Z",
"published": "2024-03-12T15:32:21Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1226"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-rejettos-http-file-server"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-C2FC-3Q38-9PF4
Vulnerability from github – Published: 2026-07-29 21:31 – Updated: 2026-07-29 21:31Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability.
The specific flaw exists within the generateFileContent function. The issue results from the lack of proper neutralization of CRLF sequences. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-29251.
{
"affected": [],
"aliases": [
"CVE-2026-12357"
],
"database_specific": {
"cwe_ids": [
"CWE-93"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-29T20:17:00Z",
"severity": "HIGH"
},
"details": "Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the generateFileContent function. The issue results from the lack of proper neutralization of CRLF sequences. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-29251.",
"id": "GHSA-c2fc-3q38-9pf4",
"modified": "2026-07-29T21:31:00Z",
"published": "2026-07-29T21:31:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12357"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-26-447"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-C3MP-RJ38-MPVH
Vulnerability from github – Published: 2026-07-28 21:31 – Updated: 2026-07-28 21:31SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by including CRLF sequences in the event payload title field delivered via webhook. Attackers can manipulate the unsanitized title field passed to the SMTP DATA command to add Bcc recipients for content exfiltration, forge the From address to bypass SPF and DKIM checks, or inject Content-Type and MIME boundary headers to corrupt message bodies for phishing.
{
"affected": [],
"aliases": [
"CVE-2026-57511"
],
"database_specific": {
"cwe_ids": [
"CWE-93"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-28T20:17:27Z",
"severity": "MODERATE"
},
"details": "SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by including CRLF sequences in the event payload title field delivered via webhook. Attackers can manipulate the unsanitized title field passed to the SMTP DATA command to add Bcc recipients for content exfiltration, forge the From address to bypass SPF and DKIM checks, or inject Content-Type and MIME boundary headers to corrupt message bodies for phishing.",
"id": "GHSA-c3mp-rj38-mpvh",
"modified": "2026-07-28T21:31:34Z",
"published": "2026-07-28T21:31:34Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57511"
},
{
"type": "WEB",
"url": "https://github.com/superplanehq/superplane/pull/6354"
},
{
"type": "WEB",
"url": "https://github.com/superplanehq/superplane/commit/428c559dd2fa0aef3ba825a434a1b05c9abc7df7"
},
{
"type": "WEB",
"url": "https://github.com/superplanehq/superplane/releases/tag/v0.30.0"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/superplane-smtp-header-injection-via-webhook-event-title"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-C4RV-J252-RMPG
Vulnerability from github – Published: 2026-04-14 18:30 – Updated: 2026-04-22 15:31CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload.
{
"affected": [],
"aliases": [
"CVE-2026-2400"
],
"database_specific": {
"cwe_ids": [
"CWE-93"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-04-14T16:16:38Z",
"severity": "MODERATE"
},
"details": "CWE-93 Improper Neutralization of CRLF Sequences (\u0027CRLF Injection\u0027) vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload.",
"id": "GHSA-c4rv-j252-rmpg",
"modified": "2026-04-22T15:31:32Z",
"published": "2026-04-14T18:30:35Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2400"
},
{
"type": "WEB",
"url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-104-01\u0026p_enDocType=Security+and+Safety+Notice\u0026p_File_Name=SEVD-2026-104-01.pdf"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
Mitigation
Avoid using CRLF as a special sequence.
Mitigation
Appropriately filter or quote CRLF sequences in user-controlled input.
CAPEC-15: Command Delimiters
An attack of this type exploits a programs' vulnerabilities that allows an attacker's commands to be concatenated onto a legitimate command with the intent of targeting other resources such as the file system or database. The system that uses a filter or denylist input validation, as opposed to allowlist validation is vulnerable to an attacker who predicts delimiters (or combinations of delimiters) not present in the filter or denylist. As with other injection attacks, the attacker uses the command delimiter payload as an entry point to tunnel through the application and activate additional attacks through SQL queries, shell commands, network scanning, and so on.
CAPEC-81: Web Server Logs Tampering
Web Logs Tampering attacks involve an attacker injecting, deleting or otherwise tampering with the contents of web logs typically for the purposes of masking other malicious behavior. Additionally, writing malicious data to log files may target jobs, filters, reports, and other agents that process the logs in an asynchronous attack pattern. This pattern of attack is similar to "Log Injection-Tampering-Forging" except that in this case, the attack is targeting the logs of the web server and not the application.