Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SymfonyComponentMimeHeaderParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Symfony | Sensiolabs | * | 5.4.52 (excluding) |
| Symfony | Sensiolabs | 6.0.0 (including) | 6.4.40 (excluding) |
| Symfony | Sensiolabs | 7.0.0 (including) | 7.4.12 (excluding) |
| Symfony | Sensiolabs | 8.0.0 (including) | 8.0.12 (excluding) |
| Symfony | Ubuntu | questing | * |
| Symfony | Ubuntu | upstream | * |