CRLF Injection is a vulnerability tracked across 5 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed December 19, 2025; most recent activity June 3, 2026.
A critical vulnerability, CVE-2026-45372, has been identified in cpp-httplib, a C++11 HTTP/HTTPS library. The flaw allows attackers to inject carriage return and newline byte pairs into HTTP header values due to…
A critical privilege escalation vulnerability chain, tracked as CVE-2026-5140, has been identified in the Pardus Linux update mechanism. This flaw allows local users to gain full root access without authentication,…
A critical CRLF injection vulnerability in the Laravel framework, tracked as CVE-2026-48019, could allow attackers to manipulate outbound email processing in affected applications. This flaw affects Laravel versions up…
Vulnerabilities have been identified in OpenJDK versions 8, 11, and 21, as well as CRaC JDK 21. The RMI component in these versions allows unauthenticated remote attackers to establish TCP endpoint connections without…
SUSE and openSUSE released updates for netty to address a moderate security issue identified as CVE-2025-67735. The vulnerability involves a lack of URI sanitization in `HttpRequestEncoder`, which can lead to CRLF…