Intel

AIKIDO-2026-10880

symfony/mime is vulnerable to CRLF Injection

CRLF InjectionCVE-2026-45070 Published May 21, 2026

65

Medium Risk

This Affects:

PHPsymfony/mime
0.0.1 - 5.4.51
Fixed in 5.4.52
6.0.0 - 6.4.39
Fixed in 6.4.40
7.0.0 - 7.4.11
Fixed in 7.4.12
8.0.0 - 8.0.11
Fixed in 8.0.12
Are you affected? Scan for Free

TL;DR

ParameterizedHeader validates parameter values but emits parameter names verbatim. A caller that derives a MIME parameter name from untrusted input can include CRLF or other non-token bytes. Pre-fix messages can contain injected headers when structured headers are serialized. The fix rejects parameter names outside the RFC token character class.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

symfony/mime is vulnerable to CRLF Injection in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.

How to fix this

Upgrade the symfony/mime and/or symfony/symfony library to the patch version.