Threadlinqs IntelligenceStart free

Weakness · BaseCWE-93

CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')

KEV-linkedBase

As of 2026-10-05, CWE-93 (CRLF Injection) underlies 5 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 10 tracked threats.

CVEs
5Mapped to CWE-93
CISA KEV
1Exploited in the wild
Critical
0CVSS v3 critical CVEs
Threats
10Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-93?

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

CWE-93 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific.

Source: MITRE CWE (CWE-93 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity — Modify Application Data

Source: MITRE CWE, common consequences.

How CWE-93 is exploited in the wild

Threadlinqs maps 5 CVEs to CWE-93, published between 2025-10-12 and 2026-09-19. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 1 high, 3 medium. The highest EPSS score in the set is 97.5% (CVE-2025-61884), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-93 directly or through a CVE it covers; the most recent is “Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)” (2026-10-02). Affected products concentrate in Exim (1), Oracle Corporation (1), netty (1), among 4 vendors in total.

Vulnerabilities (CVEs)

All 5 CVEs mapped to CWE-93, CISA KEV first, then by CVSS score.

Affected vendors

  • Exim — 1 CVE
  • Oracle Corporation — 1 CVE
  • netty — 1 CVE
  • undici — 1 CVE

Threat activity

10 tracked threats cite CWE-93:

Mitigations

  • Implementation: Avoid using CRLF as a special sequence.
  • Implementation: Appropriately filter or quote CRLF sequences in user-controlled input.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.