PT-2026-81035 · Cakephp · Cakephp

CVE-2026-77634

·

Published

2026-08-24

·

Updated

2026-09-08

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CakePHP versions prior to 4.5.12 CakePHP versions prior to 4.6.5 CakePHP versions prior to 5.1.8 CakePHP versions prior to 5.2.14 CakePHP versions prior to 5.3.7
Description Custom mail headers added via the setHeaders() or addHeaders() functions in the Message class do not have CRLF (Carriage Return Line Feed) bytes removed. This allows for header injection when user-controlled data is incorporated into message headers.
Recommendations Update to version 4.5.12 Update to version 4.6.5 Update to version 5.1.8 Update to version 5.2.14 Update to version 5.3.7

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77634
GHSA-2QH5-382H-3JPC

Affected Products

Cakephp