CVE Vulnerabilities

CVE-2026-45070

Improper Neutralization of CRLF Sequences ('CRLF Injection')

Published: Jul 14, 2026 | Modified: Jul 15, 2026
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SymfonyComponentMimeHeaderParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

Weakness

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Affected Software

NameVendorStart VersionEnd Version
SymfonySensiolabs*5.4.52 (excluding)
SymfonySensiolabs6.0.0 (including)6.4.40 (excluding)
SymfonySensiolabs7.0.0 (including)7.4.12 (excluding)
SymfonySensiolabs8.0.0 (including)8.0.12 (excluding)
SymfonyUbuntuquesting*
SymfonyUbuntuupstream*

Potential Mitigations

References