Executive brief
A vulnerability exists in the Symfony Mailer component, a popular tool used by PHP applications to send emails. The software fails to properly block line breaks in email addresses, which could allow an attacker to inject malicious commands or headers into outgoing emails. This could lead to unauthorized emails being sent or the manipulation of email content, potentially damaging a company's reputation or facilitating phishing attacks.
Technical details
A CRLF injection vulnerability (CWE-93) exists in the `Symfony\Component\Mime\Address` constructor. The component fails to neutralize line breaks (\r\n) when they are contained within a quoted string in the local-part of an email address. Because this component is treated as a security boundary for mailer addresses (To, CC, BCC, etc.), an attacker can provide a crafted email address that, when rendered into message headers or used in SMTP transport protocol lines (MAIL FROM/RCPT TO), injects new headers or SMTP commands. This can be exploited to add unauthorized recipients or modify email metadata. The issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12 by rejecting addresses containing control characters.
Affected products
- Symfony symfony/symfony < 5.4.52, >= 6.0.0-BETA1, < 6.4.40, >= 7.0.0-BETA1, < 7.4.12, >= 8.0.0-BETA1, < 8.0.12
Timeline
- 2026-05-20: patched: Fixed versions released across multiple branches.
- 2026-07-14: advisory: Security advisory published.
References
- https://github.com/symfony/symfony/commit/a1c42cbe517bc146a54da7505a107ded317478fe
- https://github.com/symfony/symfony/releases/tag/v5.4.52
- https://github.com/symfony/symfony/releases/tag/v6.4.40
- https://github.com/symfony/symfony/releases/tag/v7.4.12
- https://github.com/symfony/symfony/releases/tag/v8.0.12
- https://github.com/symfony/symfony/security/advisories/GHSA-qpmx-3rfj-7rhv