IM
IronMonkey Threat Research

CVE-2026-48019 HIGH

Published: 2026-09-04 | Last Modified: 2026-09-04 | Status: Received

Description

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in applications that send mail to user-supplied addresses. This issue has been patched in versions 12.60.0 and 13.10.0.

CVSS Metrics

Base Score: 8.9 (HIGH)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactLOW

Source: [email protected]

Type: Secondary

Exploitability Score: 2.2

Impact Score: 6.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-93
Notification
Message here