Kentico Xperience Routing Engine CRLF Injection Vulnerability

Vulnerability

A CRLF injection vulnerability has been identified in Kentico Xperience versions through 13.0.79. This vulnerability allows attackers to manipulate URL query string redirects due to improper encoding in the routing engine. Such manipulation could lead to header injection and potentially facilitate further attacks on the web application.

Impact

Exploitation of this vulnerability could allow for CRLF injection, leading to header injection and potentially further web application attacks.

Remediation

Users can apply the latest hotfix available for their Kentico Xperience version. Instructions for applying hotfixes can be found in the Kentico Xperience Documentation.

Added: Dec 18, 2025, 8:40 PM
Updated: Dec 18, 2025, 8:40 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
7.6
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.