# CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')

**KEV-linked**

> As of 2026-10-05, CWE-93 (CRLF Injection) underlies 5 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 10 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-93?

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

CWE-93 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/93.html) (CWE-93 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Integrity** — Modify Application Data

_Source: MITRE CWE, common consequences._

## How CWE-93 is exploited in the wild

Threadlinqs maps 5 CVEs to CWE-93, published between 2025-10-12 and 2026-09-19. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 1 high, 3 medium. The highest EPSS score in the set is 97.5% (CVE-2025-61884), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-93 directly or through a CVE it covers; the most recent is “Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)” (2026-10-02). Affected products concentrate in Exim (1), Oracle Corporation (1), netty (1), among 4 vendors in total.

## Vulnerabilities (CVEs)

All 5 CVEs mapped to CWE-93, CISA KEV first, then by CVSS score.

- [CVE-2025-61884](https://intel.threadlinqs.com/cve/CVE-2025-61884) — CISA KEV · CVSS 7.5 high · EPSS 97.5% · published 2025-10-12
- [CVE-2026-59921](https://intel.threadlinqs.com/cve/CVE-2026-59921) — CVSS 5.7 medium · EPSS 0.2% · published 2026-07-28
- [CVE-2026-15157](https://intel.threadlinqs.com/cve/CVE-2026-15157) — CVSS 4.2 medium · EPSS 0.1% · published 2026-07-29
- [CVE-2026-94057](https://intel.threadlinqs.com/cve/CVE-2026-94057) — CVSS 4 medium · EPSS 0.1% · published 2026-09-19
- [CVE-2026-75922](https://intel.threadlinqs.com/cve/CVE-2026-75922) — EPSS 0.2% · published 2026-08-23

## Affected vendors

- [Exim](https://intel.threadlinqs.com/vendors/exim) — 1 CVE
- **Oracle Corporation** — 1 CVE
- [netty](https://intel.threadlinqs.com/vendors/netty) — 1 CVE
- **undici** — 1 CVE

## Threat activity

10 tracked threats cite CWE-93:

- [Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)](https://intel.threadlinqs.com/threat/TL-2026-2902) — CRITICAL · 2026-10-02
- [Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection](https://intel.threadlinqs.com/threat/TL-2026-2478) — MEDIUM · 2026-09-13
- [Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers (CVE-2026-41940)](https://intel.threadlinqs.com/threat/TL-2026-1681) — CRITICAL · 2026-07-25
- [Critical Ubuntu Pro Client Vulnerability Enables Root Code Execution via Contract Server Spoofing (CVE-2026-11386)](https://intel.threadlinqs.com/threat/TL-2026-1564) — CRITICAL · 2026-07-20
- [CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission Exploited Before Public PoC](https://intel.threadlinqs.com/threat/TL-2026-1089) — CRITICAL · 2026-07-02
- [Wazuh Manager 5.0 inventory_sync NDJSON Injection in OpenSearch _bulk API (GHSA-ff9g-85jq-r3g3, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-0800) — CRITICAL · 2026-06-15
- [Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0758) — CRITICAL · 2026-06-10
- [Laravel Framework CRLF Injection (CVE-2026-48019) — Outbound Email Header/Content Manipulation (CWE-93)](https://intel.threadlinqs.com/threat/TL-2026-0677) — HIGH · 2026-06-03
- [Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers Compromised)](https://intel.threadlinqs.com/threat/TL-2026-0449) — CRITICAL · 2026-05-02
- [GitHub.com & GitHub Enterprise Server Pre-Auth RCE via X-Stat Header Field Injection (CVE-2026-3854)](https://intel.threadlinqs.com/threat/TL-2026-0434) — HIGH · 2026-04-29

## Mitigations

- **Implementation**: Avoid using CRLF as a special sequence.
- **Implementation**: Appropriately filter or quote CRLF sequences in user-controlled input.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-74 Injection](https://intel.threadlinqs.com/cwe/CWE-74)
- [CWE-117](https://cwe.mitre.org/data/definitions/117.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-93
Source definition: https://cwe.mitre.org/data/definitions/93.html
Detection rules and IOCs for threats exploiting CWE-93 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
