CVE-2025-53094 | ESP32Async ESPAsyncWebServer up to 3.7.8 on ESP32/ESP8266/RP2040/RP2350 HTTP Header AsyncWebHeader.cpp crlf injection (GHSA-87j8-6f7g-h8wh / EUVD-2025-19427)
A vulnerability, which was classified as problematic, has been found in ESP32Async ESPAsyncWebServer up to 3.7.8 on ESP32/ESP8266/RP2040/RP2350. Affected by this issue is some unknown functionality of the file AsyncWebHeader.cpp of the component HTTP Header Handler. The manipulation leads to crlf injection.
This vulnerability is handled as CVE-2025-53094. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.