CRLF injection in Symfony - CVE-2026-45067
Published: May 21, 2026
Symfony
Detailed vulnerability description
The vulnerability allows a remote attacker to inject arbitrary email headers or SMTP commands.
The vulnerability exists due to improper neutralization of CRLF sequences in Symfony\Component\Mime\Address when processing a quoted-string email address containing raw line breaks. A remote attacker can supply a specially crafted email address to inject arbitrary email headers or SMTP commands.
The issue affects addresses that are later emitted into rendered message headers or SMTP MAIL FROM and RCPT TO protocol lines.