目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-93 对CRLF序列的转义处理不恰当(CRLF注入) 类漏洞列表 178

CWE-93 对CRLF序列的转义处理不恰当(CRLF注入) 类弱点 178 条 CVE 漏洞汇总,含 AI 中文分析。

CRLF注入是一种输入验证缺陷,指程序未正确过滤用户输入中的回车换行符。攻击者利用此漏洞注入恶意CRLF序列,篡改HTTP响应头或伪造日志,进而实施会话劫持、跨站脚本或缓存投毒。开发者应严格对用户输入进行白名单验证,确保仅包含合法字符,并在使用输入前自动转义或移除CRLF序列,以阻断注入路径。

MITRE CWE 官方描述
CWE:CWE-93 CRLF序列(CRLF Injection)的不当中和 英文:产品将CRLF(回车换行符)作为特殊元素使用,例如用于分隔行或记录,但未对输入中的CRLF序列进行中和,或中和不当。
常见影响 (1)
Integrity Modify Application Data
缓解措施 (2)
Implementation Avoid using CRLF as a special sequence.
Implementation Appropriately filter or quote CRLF sequences in user-controlled input.
代码示例 (2)
The following code segment reads the name of the author of a weblog entry, author, from an HTTP request and sets it in a cookie header of an HTTP response.
String author = request.getParameter(AUTHOR_PARAM); ... Cookie cookie = new Cookie("author", author); cookie.setMaxAge(cookieExpiration); response.addCookie(cookie);
Bad · Java
HTTP/1.1 200 OK ... Set-Cookie: author=Jane Smith ...
Result
The following code is a workflow job written using YAML. The code attempts to download pull request artifacts, unzip from the artifact called pr.zip and extract the value of the file NR into a variable "pr_number" that will be used later in another job. It attempts to create a github workflow environment variable, writing to $GITHUB_ENV. The environment …
name: Deploy Preview jobs: deploy: runs-on: ubuntu-latest steps: - name: 'Download artifact' uses: actions/github-script with: script: | var artifacts = await github.actions.listWorkflowRunArtifacts({ owner: context.repo.owner, repo: context.repo.repo, run_id: ${{ github.event.workflow_run.id }}, }); var matchPrArtifact = artifacts.data.artifacts.filter((artifact) => { return artifact.name == "pr" })[0]; var downloadPr = await github.actions.downloadArtifact({ owner: context.repo.owner, repo: context.repo.repo, artifact_id: matchPrArtifact.id, archive_format: 'zip', }); var fs = require('fs');
Bad · Other
\nNODE_OPTIONS="--experimental-modules --experiments-loader=data:text/javascript,console.log('injected code');//"
Attack
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-82973 docker-mailbox CRLF注入漏洞 — docker-mailbox 9.4 Critical 2026-09-29
CVE-2026-100717 Froxlor 2.3.12 前版本 validateUrl userinfo CRLF 注入漏洞 — froxlor 9.9 Critical 2026-09-26
CVE-2026-91841 NetworkManager-vpnc 2018-10900 不完整修复导致root权限提升漏洞 — NetworkManager-vpnc 7.8 High 2026-09-25
CVE-2026-91840 networkmanager-vpnc 本地提权漏洞 — NetworkManager-vpnc 7.8 High 2026-09-25
CVE-2026-91839 NetworkManager-FortisslVPN本地权限提升漏洞 — NetworkManager-fortisslvpn 7.8 High 2026-09-25
CVE-2026-61815 zbateson/mail-mime-parser CRLF头部注入漏洞 — mail-mime-parser 7.2 High 2026-09-24
CVE-2026-90990 Livestatus 监控过滤值注入漏洞 — Checkmk 5.3 Medium 2026-09-22
CVE-2026-55159 luci-app-adblock-fast 命令注入漏洞 — luci-app-adblock-fast 8.8 High 2026-09-21
CVE-2026-94057 Exim 4.100.1 前 SMTP 走私漏洞 — Exim 4.0 Medium 2026-09-19
CVE-2026-93576 Netty SMTP命令名CRLF校验不完整漏洞 — Red Hat build of Apache Camel for Spring Boot 4 7.5 High 2026-09-18
CVE-2026-40530 群晖DSM特定版本User API CRLF注入漏洞 — DiskStation Manager (DSM) 8.0 High 2026-09-18
CVE-2026-13666 群晖DSM共享API CRLF注入致文件写入漏洞 — DiskStation Manager (DSM) 3.5 Low 2026-09-18
CVE-2026-90937 Froxlor 输入验证错误漏洞 — froxlor 9.9 Critical 2026-09-14
CVE-2026-90767 Froxlor 输入验证错误漏洞 — Froxlor 6.5 Medium 2026-09-13
CVE-2026-48019 Laravel framework 输入验证错误漏洞 — framework 8.9 High 2026-09-04
CVE-2026-75925 IXON VPN Client 输入验证错误漏洞 — IXON VPN Client 9.6 Critical 2026-09-04
CVE-2026-84962 MongoDB libmongocrypt 输入验证错误漏洞 — libmongocrypt 4.2 Medium 2026-09-03
CVE-2026-84379 Pydantic HTTPX2 输入验证错误漏洞 — httpx2 5.3 Medium 2026-09-02
CVE-2026-84372 Predis 输入验证错误漏洞 — predis 9.8 Critical 2026-09-01
CVE-2026-82854 Nodemailer 输入验证错误漏洞 — nodemailer 9.8 Critical 2026-08-31
CVE-2026-82853 Nodemailer 输入验证错误漏洞 — nodemailer 4.9 Medium 2026-08-31
CVE-2026-82661 Nodemailer 输入验证错误漏洞 — nodemailer 5.4 Medium 2026-08-31
CVE-2026-33606 Open-Xchange Dovecot Pro 输入验证错误漏洞 — OX Dovecot Pro 4.8 Medium 2026-08-28
CVE-2026-77341 yhirose cpp-httplib 输入验证错误漏洞 — cpp-httplib 5.3 Medium 2026-08-27
CVE-2026-54511 syslog 日志注入漏洞 — logtape 8.6 High 2026-08-26
CVE-2026-77550 Ubiquiti UniFi OS Server 输入验证错误漏洞 — UniFi OS Server 10.0 Critical 2026-08-26
CVE-2026-77549 Ubiquiti UniFi OS Server 输入验证错误漏洞 — UniFi OS Server 9.0 Critical 2026-08-26
CVE-2026-77634 cakephp 输入验证错误漏洞 — cakephp 8.2 High 2026-08-24
CVE-2026-74866 Fastify busboy 输入验证错误漏洞 — @fastify/busboy 5.8 Medium 2026-08-21
CVE-2026-75484 Mat Trudel Bandit 输入验证错误漏洞 — bandit 6.9 Medium 2026-08-20

CWE-93(对CRLF序列的转义处理不恰当(CRLF注入)) 是常见的弱点类别,本平台收录该类弱点关联的 178 条 CVE 漏洞。