PT-2026-44136 · Symfony · Symfony

Published

2026-05-21

·

Updated

2026-05-27

·

CVE-2026-45067

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Symfony versions prior to 5.4.21
Description The SymfonyComponentMimeAddress constructor fails to properly validate email addresses when the local-part is a quoted string containing raw carriage return and line feed (r ) bytes. This allows an attacker to embed CRLF sequences, which are later emitted verbatim into rendered message headers and SmtpTransport protocol lines such as MAIL FROM:<...> and RCPT TO:<...>. This behavior can lead to the injection of new mail headers or additional SMTP commands.
Recommendations Update to version 5.4.21 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-45067
GHSA-QPMX-3RFJ-7RHV

Affected Products

Symfony