CRLF injection in Symfony - CVE-2026-45067
Published: May 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary email headers or SMTP commands.
The vulnerability exists due to improper neutralization of CRLF sequences in Symfony\Component\Mime\Address when processing a quoted-string email address containing raw line breaks. A remote attacker can supply a specially crafted email address to inject arbitrary email headers or SMTP commands.
The issue affects addresses that are later emitted into rendered message headers or SMTP MAIL FROM and RCPT TO protocol lines.
Affected software
Debian Linux
symfony (Debian package)
How to mitigate CVE-2026-45067
symfony (Debian package) - addressed in versions 5.4.53+dfsg-0+deb12u1, 6.4.41+dfsg-0+deb13u1