PT-2026-44136 · Symfony · Symfony

CVE-2026-45067

·

Published

2026-05-21

·

Updated

2026-07-14

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Symfony versions prior to 5.4.21
Description The SymfonyComponentMimeAddress constructor fails to properly validate email addresses when the local-part is a quoted string containing raw carriage return and line feed (r ) bytes. This allows an attacker to embed CRLF sequences, which are later emitted verbatim into rendered message headers and SmtpTransport protocol lines such as MAIL FROM:<...> and RCPT TO:<...>. This behavior can lead to the injection of new mail headers or additional SMTP commands.
Recommendations Update to version 5.4.21 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45067
GHSA-QPMX-3RFJ-7RHV

Affected Products

Symfony