CVE Vulnerabilities

CVE-2025-41376

Improper Neutralization of CRLF Sequences ('CRLF Injection')

Published: Aug 01, 2025 | Modified: Jan 30, 2026
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

CRLF Injection vulnerability in Limesurvey v2.65.1+170522.  This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via /index.php/survey/index/sid//token/fwyfw%0d%0aCookie:%20POC.

Weakness

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Affected Software

NameVendorStart VersionEnd Version
LimesurveyLimesurvey2.65.1 (including)3.0.0 (excluding)

Potential Mitigations

References