Junglewise Threat Intelligence

CVE-2026-45070: Symfony Mime CRLF injection in ParameterizedHeader

CVE-2026-45070 · Severity: medium · CVSS 4 · Published 2026-07-14

Technologies: Symfony Mime. Vendors: Symfony.

Executive brief

Symfony is a popular PHP framework used to build web applications. A vulnerability in its email handling component could allow an attacker to inject malicious headers into outgoing emails if the application uses untrusted input to name email parameters. This could be used to bypass security filters, redirect replies, or perform other email-based attacks, potentially damaging a company's reputation or facilitating phishing.

Technical details

A CRLF injection vulnerability exists in the Symfony\Component\Mime\Header\ParameterizedHeader class. While the component validates and encodes parameter values, it fails to sanitize parameter names, emitting them verbatim in the rendered mail headers. If an application derives a parameter name from untrusted user input, an attacker can include CRLF sequences or other non-token bytes to inject additional, arbitrary headers into structured mail headers like Content-Type or Content-Disposition. This is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12 by rejecting parameter names containing non-token characters.

Affected products

  • Symfony symfony/symfony < 5.4.52, >= 6.0.0-BETA1 < 6.4.40, >= 7.0.0-BETA1 < 7.4.12, >= 8.0.0-BETA1 < 8.0.12
  • Symfony symfony/mime < 5.4.52, >= 6.0.0-BETA1 < 6.4.40, >= 7.0.0-BETA1 < 7.4.12, >= 8.0.0-BETA1 < 8.0.12

Timeline

  • 2026-07-14: advisory: NVD publication date
  • 2026-05-20: patched: Release of fixed versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12

References

Related threats