#VU126262 CRLF injection in DiskStation Manager (DSM) - CVE-2026-40530
Published: April 16, 2026
DiskStation Manager (DSM)
Synology Inc.
Description
The vulnerability allows a remote user to read or write arbitrary files and cause a denial of service.
The vulnerability exists due to improper neutralization of CRLF sequences in DSM when handling crafted input. A remote user can send specially crafted input to read or write arbitrary files and cause a denial of service.
User interaction is required.