目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-93 对CRLF序列的转义处理不恰当(CRLF注入) 类漏洞列表 178

CWE-93 对CRLF序列的转义处理不恰当(CRLF注入) 类弱点 178 条 CVE 漏洞汇总,含 AI 中文分析。

CRLF注入是一种输入验证缺陷,指程序未正确过滤用户输入中的回车换行符。攻击者利用此漏洞注入恶意CRLF序列,篡改HTTP响应头或伪造日志,进而实施会话劫持、跨站脚本或缓存投毒。开发者应严格对用户输入进行白名单验证,确保仅包含合法字符,并在使用输入前自动转义或移除CRLF序列,以阻断注入路径。

MITRE CWE 官方描述
CWE:CWE-93 CRLF序列(CRLF Injection)的不当中和 英文:产品将CRLF(回车换行符)作为特殊元素使用,例如用于分隔行或记录,但未对输入中的CRLF序列进行中和,或中和不当。
常见影响 (1)
Integrity Modify Application Data
缓解措施 (2)
Implementation Avoid using CRLF as a special sequence.
Implementation Appropriately filter or quote CRLF sequences in user-controlled input.
代码示例 (2)
The following code segment reads the name of the author of a weblog entry, author, from an HTTP request and sets it in a cookie header of an HTTP response.
String author = request.getParameter(AUTHOR_PARAM); ... Cookie cookie = new Cookie("author", author); cookie.setMaxAge(cookieExpiration); response.addCookie(cookie);
Bad · Java
HTTP/1.1 200 OK ... Set-Cookie: author=Jane Smith ...
Result
The following code is a workflow job written using YAML. The code attempts to download pull request artifacts, unzip from the artifact called pr.zip and extract the value of the file NR into a variable "pr_number" that will be used later in another job. It attempts to create a github workflow environment variable, writing to $GITHUB_ENV. The environment …
name: Deploy Preview jobs: deploy: runs-on: ubuntu-latest steps: - name: 'Download artifact' uses: actions/github-script with: script: | var artifacts = await github.actions.listWorkflowRunArtifacts({ owner: context.repo.owner, repo: context.repo.repo, run_id: ${{ github.event.workflow_run.id }}, }); var matchPrArtifact = artifacts.data.artifacts.filter((artifact) => { return artifact.name == "pr" })[0]; var downloadPr = await github.actions.downloadArtifact({ owner: context.repo.owner, repo: context.repo.repo, artifact_id: matchPrArtifact.id, archive_format: 'zip', }); var fs = require('fs');
Bad · Other
\nNODE_OPTIONS="--experimental-modules --experiments-loader=data:text/javascript,console.log('injected code');//"
Attack
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-1536 libsoup 注入漏洞 — Red Hat Enterprise Linux 10 5.8 Medium 2026-01-28
CVE-2026-1467 libsoup 注入漏洞 — Red Hat Enterprise Linux 10 5.8 Medium 2026-01-27
CVE-2026-24489 gakido 注入漏洞 — gakido 5.3 Medium 2026-01-27
CVE-2026-1299 CPython 安全漏洞 — CPython 4.3 - 2026-01-23
CVE-2026-23953 Incus 注入漏洞 — incus 8.7 High 2026-01-22
CVE-2026-0672 CPython 安全漏洞 — CPython 4.3AI Medium AI 2026-01-20
CVE-2025-15282 CPython 安全漏洞 — CPython 5.3AI Medium AI 2026-01-20
CVE-2026-23829 Mailpit 安全漏洞 — mailpit 5.3 Medium 2026-01-18
CVE-2026-22777 ComfyUI-Manager 注入漏洞 — ComfyUI-Manager 7.5 High 2026-01-10
CVE-2026-21428 cpp-httplib 注入漏洞 — cpp-httplib 9.1 - 2026-01-01
CVE-2022-50682 Kentico Xperience 注入漏洞 — Xperience 6.5 Medium 2025-12-18
CVE-2025-67735 Netty 注入漏洞 — netty 6.5 Medium 2025-12-16
CVE-2025-14531 Code-Projects Rental Management System 注入漏洞 — Rental Management System 4.3 Medium 2025-12-11
CVE-2025-54972 Fortinet FortiMail 注入漏洞 — FortiMail 3.9 Medium 2025-11-18
CVE-2025-59151 Pi-Hole Adminlte 注入漏洞 — web 8.2 High 2025-10-27
CVE-2025-59419 Netty 注入漏洞 — netty 9.8 - 2025-10-15
CVE-2025-57804 python-hyper h2 注入漏洞 — h2 7.5AI High AI 2025-08-25
CVE-2025-8715 PostgreSQL 安全漏洞 — PostgreSQL 8.8 High 2025-08-14
CVE-2025-8419 Keycloak 注入漏洞 — keycloak 5.3 Medium 2025-08-06
CVE-2025-41376 TESI Gandia Integra Total SQL注入漏洞 — LimeSurvey 8.8 - 2025-08-01
CVE-2025-6175 DECE Software Geodi 注入漏洞 — Geodi 7.2 High 2025-07-29
CVE-2025-0293 Ivanti Connect Secure和Ivanti Policy Secure 注入漏洞 — Connect Secure 6.6 Medium 2025-07-08
CVE-2025-53094 ESPAsyncWebServer 注入漏洞 — ESPAsyncWebServer 5.8AI Medium AI 2025-06-27
CVE-2025-52479 Julia URIs.jl 注入漏洞 — HTTP.jl 5.4AI Medium AI 2025-06-25
CVE-2025-40671 AES Multimedia Gestnet 注入漏洞 — Gestnet 9.8AI Critical AI 2025-05-26
CVE-2024-53693 QNAP Systems QTS和QNAP Systems QuTS hero 代码注入漏洞 — QTS 4.3 - 2025-03-07
CVE-2024-50405 QNAP Systems QTS和QNAP Systems QuTS hero 代码注入漏洞 — QTS 2.7 - 2025-03-07
CVE-2025-27111 Rack 安全漏洞 — rack 5.3 - 2025-03-04
CVE-2025-25184 Rack 安全漏洞 — rack 4.3 - 2025-02-12
CVE-2024-48868 QNAP Systems QTS和QuTS hero 安全漏洞 — QTS 5.3 - 2024-12-06

CWE-93(对CRLF序列的转义处理不恰当(CRLF注入)) 是常见的弱点类别,本平台收录该类弱点关联的 178 条 CVE 漏洞。