CRLF Injection Vulnerability in Laravel Framework
CVE-2026-48019

8.9HIGH

Key Information:

Vendor

Laravel

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-48019?

A CRLF injection vulnerability exists in Laravel's email validation prior to version 12.60.0 and 13.10.0. This flaw, in conjunction with how Symfony Mailer and Symfony Mime process certain character sequences, may allow unauthenticated attackers to exploit outgoing email processes. The vulnerability poses a risk of interference in email communications handled by applications. Users are advised to upgrade to the patched versions 12.60.0 or 13.10.0 to mitigate this issue.

Affected Version(s)

framework >= 13.0.0, < 13.10.0 < 13.0.0, 13.10.0

framework < 12.60.0 < 12.60.0

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.