CVE-2026-93576
7.5 HIGHPublished 2026-09-18 · Updated 2026-09-18
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this field, can embed CR/LF characters to inject arbitrary SMTP commands. This can lead to SMTP command smuggling, allowing for unauthorized email relay or spoofing of sender/recipient addresses. While the impact is significant, the real-world exploitability is considered lower as applications typically do not place user-controlled data in the command-name field.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses
CWE-93
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-100717PoC
- LOWCVE-2026-13666
- HIGHCVE-2026-40530
- HIGHCVE-2026-55159PoC
- HIGHCVE-2026-61815PoC
- UNSCOREDCVE-2026-90990
- HIGHCVE-2026-91839
- HIGHCVE-2026-91840
Related by shared AI tags and CWE weakness class. Browse the full archive.