SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-48019

HIGH · CVSS 8.9 EPSS 0.68% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Laravel's email validation prior to versions 12.60.0 and 13.10.0 is vulnerable to a CRLF injection, which could enable unauthenticated attackers to manipulate outbound email processing, potentially leading to phishing or spam attacks. Organizations using affected versions of Laravel that handle user-supplied email addresses should prioritize updating to the patched versions to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-48019
Severity
HIGH
CVSS
8.9
EPSS
0.68%

Original NVD Description

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in applications that send mail to user-supplied addresses. This issue has been patched in versions 12.60.0 and 13.10.0.