Intel

AIKIDO-2026-10881

symfony/mime is vulnerable to CRLF Injection

CRLF InjectionCVE-2026-45067 Published May 21, 2026

65

Medium Risk

This Affects:

PHPsymfony/mime
0.0.1 - 5.4.51
Fixed in 5.4.52
6.0.0 - 6.4.39
Fixed in 6.4.40
7.0.0 - 7.4.11
Fixed in 7.4.12
8.0.0 - 8.0.11
Fixed in 8.0.12
Are you affected? Scan for Free

TL;DR

Address accepts email addresses that contain raw line breaks inside quoted local parts. Those addresses later flow into rendered mail headers and SMTP protocol commands. Pre-fix applications can allow CRLF injection into message headers or SMTP commands when addresses are influenced by untrusted input. The fix rejects addresses containing line breaks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

symfony/mime is vulnerable to CRLF Injection in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.

How to fix this

Upgrade the symfony/mime and/or symfony/symfony library to the patch version.