CRLF Injection - Vulnerability

Threat entity extracted from intelligence sources

Frequency
17
occurrences
First Seen
December 19, 2025
Last Seen
August 26, 2026

Related Threat Clusters

Recent Intelligence Reports

  • Ubiquiti patches three max severity security vulnerabilities — Bleepingcomputer · August 26, 2026
  • Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing — Cybersecuritynews · June 3, 2026
  • CVE-2026-45372: cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection [CRITICAL] CVSS 9.9 Exploit Intelligence — Recent CVEs / 16h cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity check (is_field_value) is run before decoding, so encod — exploit-intel.com · May 30, 2026
  • Pardus Linux Vulnerability Chain Enables Complete System Takeover — Thecyberexpress · May 21, 2026
  • Ubuntu 25.10 OpenJDK 17 Critical Risk RCE DoS USN-7998 — Linuxsecurity · February 3, 2026
  • Ubuntu 25.10 OpenJDK 17 Important RMI Info Disclosure 7997-1 CVE-2026 — Linuxsecurity · February 3, 2026
  • Ubuntu 25.10 OpenJDK 25 Critical RCE Information Disclosure 7996 — Linuxsecurity · February 3, 2026
  • Ubuntu 25 OpenJDK 25 Important Security Threats USN-7995 — Linuxsecurity · February 3, 2026

CVSS v3.1 Breakdown