CRLF Injection Affecting kentico.xperience.aspnetcore.webapp package, versions [,13.0.80)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about CRLF Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DOTNET-KENTICOXPERIENCEASPNETCOREWEBAPP-14545481
  • published21 Dec 2025
  • disclosed18 Dec 2025
  • creditTom Waldman

Introduced: 18 Dec 2025

NewCVE-2022-50682  (opens in a new tab)
CWE-93  (opens in a new tab)

How to fix?

Upgrade Kentico.Xperience.AspNetCore.WebApp to version 13.0.80 or higher.

Overview

Kentico.Xperience.AspNetCore.WebApp is an assemblies and content items required to integrate Kentico Xperience into ASP.NET Core applications.

Affected versions of this package are vulnerable to CRLF Injection due to improper encoding of the URL query string in the PageRedirectionContext.GetUrl() method in the routing engine. An attacker can inject arbitrary HTTP headers by crafting malicious query string parameters containing CRLF characters during page redirection.

CVSS Base Scores

version 4.0
version 3.1