symfony/mime is vulnerable to CRLF Injection
65
Medium Risk
Address accepts email addresses that contain raw line breaks inside quoted local parts. Those addresses later flow into rendered mail headers and SMTP protocol commands. Pre-fix applications can allow CRLF injection into message headers or SMTP commands when addresses are influenced by untrusted input. The fix rejects addresses containing line breaks.
You are affected if you are using a version that falls within the vulnerable range.
symfony/mime is vulnerable to CRLF Injection in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.
Upgrade the symfony/mime and/or symfony/symfony library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant