What is CWE-93?
The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.
CWE-93 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific.
Source: MITRE CWE (CWE-93 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Integrity — Modify Application Data
Source: MITRE CWE, common consequences.
How CWE-93 is exploited in the wild
Threadlinqs maps 5 CVEs to CWE-93, published between 2025-10-12 and 2026-09-19. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 1 high, 3 medium. The highest EPSS score in the set is 97.5% (CVE-2025-61884), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-93 directly or through a CVE it covers; the most recent is “Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)” (2026-10-02). Affected products concentrate in Exim (1), Oracle Corporation (1), netty (1), among 4 vendors in total.
Vulnerabilities (CVEs)
All 5 CVEs mapped to CWE-93, CISA KEV first, then by CVSS score.
- CVE-2025-61884 — CISA KEV · CVSS 7.5 high · EPSS 97.5% · published 2025-10-12
- CVE-2026-59921 — CVSS 5.7 medium · EPSS 0.2% · published 2026-07-28
- CVE-2026-15157 — CVSS 4.2 medium · EPSS 0.1% · published 2026-07-29
- CVE-2026-94057 — CVSS 4 medium · EPSS 0.1% · published 2026-09-19
- CVE-2026-75922 — EPSS 0.2% · published 2026-08-23
Affected vendors
Threat activity
10 tracked threats cite CWE-93:
- Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)CRITICAL
- Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment InjectionMEDIUM
- Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers (CVE-2026-41940)CRITICAL
- Critical Ubuntu Pro Client Vulnerability Enables Root Code Execution via Contract Server Spoofing (CVE-2026-11386)CRITICAL
- CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission Exploited Before Public PoCCRITICAL
- Wazuh Manager 5.0 inventory_sync NDJSON Injection in OpenSearch _bulk API (GHSA-ff9g-85jq-r3g3, CVSS 10.0)CRITICAL
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass ExploitationCRITICAL
- Laravel Framework CRLF Injection (CVE-2026-48019) — Outbound Email Header/Content Manipulation (CWE-93)HIGH
- Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers Compromised)CRITICAL
- GitHub.com & GitHub Enterprise Server Pre-Auth RCE via X-Stat Header Field Injection (CVE-2026-3854)HIGH
Mitigations
- Implementation: Avoid using CRLF as a special sequence.
- Implementation: Appropriately filter or quote CRLF sequences in user-controlled input.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.