logging-formatter-anticrlf
Python logging Formatter for CRLF Injection (CWE-93 / CWE-117) prevention
Decision gist · record as of 2026-08-14
Yes, if you log untrusted user input or need to prevent log injection attacks. The package is low-friction (no dependencies), permissively licensed, and has no known vulnerabilities. Maintenance is dormant but the code is stable and the attack surface is minimal. Install it as a standard practice in security-conscious logging setups; the one-line formatter swap makes adoption trivial.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low friction: pure Python wheel with no runtime dependencies.
- Maintenance is dormant (last commit 2024-02-23, 1051 days since release), but the package is archived=false and has no known vulnerabilities, suggesting it is stable rather than abandoned.
License · maintenance · safety
BSD-2-clause (permissive) — BSD-2-clause is permissive and imposes minimal restrictions on use or redistribution, making it suitable for most projects without licensing concerns.
last release 2023-09-28 (1051 days) · last repo commit 2024-02-23 · 6 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 185,546 downloads/mo, #10,008 on PyPI
Alternatives
Verify before relying
import logging
import anticrlf
handler = logging.StreamHandler()
handler.setFormatter(anticrlf.LogFormatter('%(levelname)s - %(message)s'))
logger = logging.getLogger(__name__)
logger.addHandler(handler)
logger.info("Text with newline\nhere") # outputs escaped as \n, not a line break- Whether the package is actively maintained or if dormant status reflects intentional stability rather than abandonment.
- Whether Python version support is truly unspecified or if there are practical constraints not documented in the fact sheet.
What it is and what it does
logging-formatter-anticrlf is a security-focused logging formatter that prevents CRLF injection attacks by escaping carriage returns (\r) and linefeeds (\n) in log messages. It wraps Python's standard logging.Formatter with identical construction arguments, so it works as a drop-in replacement in existing logging configurations. By default, CR and LF characters are replaced with their escaped equivalents (\r and \n), preventing attackers from injecting fake log entries or manipulating log output when logs are displayed in browsers or parsed by downstream tools.
The package includes a SubstitutionMap object that manages replacements with built-in safety checks: it prevents you from replacing unsafe characters with other unsafe characters, and it resets to safe defaults if you accidentally assign an unsafe configuration. This design protects against common mistakes where a developer might inadvertently weaken the sanitization. The package addresses CWE-93 (log injection) and CRLF-based forms of CWE-117 (improper output neutralization), though it does not handle all CWE-117 variants such as XSS flaws in browser-rendered logs.
Use it for
- Secure web applications that log user input or request data to prevent attackers from injecting fake log entries or log forging.
- Systems where logs are aggregated, parsed, or displayed in tools that interpret CR/LF as structural delimiters.
- Compliance-focused projects that need to demonstrate log integrity and prevent log tampering via injection.
- Applications handling untrusted input (API requests, form submissions) that must sanitize before logging.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you log untrusted user input or need to prevent log injection attacks.
The package is low-friction (no dependencies), permissively licensed, and has no known vulnerabilities. Maintenance is dormant but the code is stable and the attack surface is minimal. Install it as a standard practice in security-conscious logging setups; the one-line formatter swap makes adoption trivial.
Install
logging-formatter-anticrlf on PyPI
Before you install
Low friction: pure Python wheel with no runtime dependencies. Maintenance is dormant (last commit 2024-02-23, 1051 days since release), but the package is archived=false and has no known vulnerabilities, suggesting it is stable rather than abandoned.
License in practice
BSD-2-clause is permissive and imposes minimal restrictions on use or redistribution, making it suitable for most projects without licensing concerns.
Quickstart
import logging
import anticrlf
handler = logging.StreamHandler()
handler.setFormatter(anticrlf.LogFormatter('%(levelname)s - %(message)s'))
logger = logging.getLogger(__name__)
logger.addHandler(handler)
logger.info("Text with newline\nhere") # outputs escaped as \n, not a line break
Verify before relying
- Whether the package is actively maintained or if dormant status reflects intentional stability rather than abandonment.
- Whether Python version support is truly unspecified or if there are practical constraints not documented in the fact sheet.
Package facts
| License | BSD-2-clause permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Dormant 1,051 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 185,546 / month, #10,008 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
Evidence: logging_formatter_anticrlf-1.2.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “CRLF injection prevention logging”
- logging-formatter-anticrlfA drop-in replacement for Python's standard logging.Formatter that…
- defusedcsvDefusedcsv is a drop-in replacement for Python's standard csv module…
- MarkupSafeMarkupSafe provides a text object that escapes special characters so…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also logfmter · defusedcsv · MarkupSafe · jsonformatter · flake8-logging-format · logzero · linear-tsv · shellescape · minilog · bandit-sarif-formatter