Robuta

https://advisories.gitlab.com/swift/github.com/swift-server/async-http-client/CVE-2023-0040/ Async HTTP Client has CRLF Injection vulnerability in HTTP request headers | GitLab Advisory... CVE-2023-0040 Async HTTP Client has CRLF Injection vulnerability in HTTP request headers: Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a... http clientcrlf injection https://github.com/mybb/mybb/security/advisories/GHSA-f626-53q9-pqm9 Email User CRLF injection · Advisory · mybb/mybb · GitHub GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects. email usercrlf injectionadvisorymybbgithub https://advisories.gitlab.com/npm/basic-ftp/GHSA-6v7q-wjvx-w8wg/ basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via... GHSA-6v7q-wjvx-w8wg basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands: basic-ftp's CRLF... crlf injectioncommand executionbasicftpincomplete https://advisories.gitlab.com/npm/undici/CVE-2026-1527/ Undici has CRLF Injection in undici via `upgrade` option | GitLab Advisory Database (GLAD) CVE-2026-1527 Undici has CRLF Injection in undici via `upgrade` option: When an application passes user-controlled input to the upgrade option of... crlf injection https://advisories.gitlab.com/npm/axios/CVE-2026-42037/ Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream |... CVE-2026-42037 Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream: The FormDataPart constructor in... https://advisories.gitlab.com/npm/basic-ftp/GHSA-chqc-8p9q-pq6q/ basic-ftp has FTP Command Injection via CRLF | GitLab Advisory Database (GLAD) GHSA-chqc-8p9q-pq6q basic-ftp has FTP Command Injection via CRLF: basic-ftp version 5.2.0 allows FTP command injection via CRLF sequences (\r\n) in file path... command injectionbasicftp https://thehackernews.com/2025/01/critical-rce-flaw-in-gfi-keriocontrol.html Critical RCE Flaw in GFI KerioControl Allows Remote Code Execution via CRLF Injection CVE-2024-52875, a critical RCE flaw in GFI KerioControl firewalls, allows HTTP response splitting and exploits over 23,800 internet-exposed instances remote code execution https://advisories.gitlab.com/pypi/aiohttp/CVE-2023-49082/ aiohttp's ClientSession is vulnerable to CRLF injection via method | GitLab Advisory Database (GLAD) CVE-2023-49082 aiohttp's ClientSession is vulnerable to CRLF injection via method: Improper validation makes it possible for an attacker to modify the HTTP... https://advisories.gitlab.com/nuget/mimekit/CVE-2026-30227/ MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email... CVE-2026-30227 MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Injection and Email Forgery: A CRLF Injection vulnerability in MimeKit... https://advisories.gitlab.com/pypi/aiohttp/CVE-2023-49081/ aiohttp's ClientSession is vulnerable to CRLF injection via version | GitLab Advisory Database... CVE-2023-49081 aiohttp's ClientSession is vulnerable to CRLF injection via version: Improper validation make it possible for an attacker to modify the HTTP... https://bugzilla.mozilla.org/show_bug.cgi?id=1731522 1731522 - HTTP/2 header name CRLF injection RESOLVED (manuel) in Core - Networking: HTTP. Last updated 2022-08-27. httpheadernamecrlfinjection https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-43882/ AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event... CVE-2026-43882 AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing: The unauthenticated...