CVE-2026-40530: CRLF Injection
An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Synology DiskStation Manager (DSM) User APIto a version that resolves this vulnerability.Fixed in 7.2.1-69057-10 - Upgrade
Upgrade
Synology DiskStation Manager (DSM) User APIto a version that resolves this vulnerability.Fixed in 7.2.2-72806-7 - Upgrade
Upgrade
Synology DiskStation Manager (DSM) User APIto a version that resolves this vulnerability.Fixed in 7.3.2-86009-2
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to access the DSM User API remotely and authenticate with an account. The supplied data does not indicate that unauthenticated attackers can exploit it.
What impact can exploitation have?
A successful attacker can read or write arbitrary files and cause denial of service. The denial-of-service impact occurs after the affected system is rebooted.
Which DSM releases need to be updated?
Update DSM to 7.2.1-69057-10, 7.2.2-72806-7, or 7.3.2-86009-2, as applicable. Earlier releases in those version lines are affected according to the advisory information provided.