• PoC PUBLIC

CVE-2026-48019: pre-auth crlf injection in laravel framework

An unauthenticated attacker can exploit a CRLF injection flaw in the Laravel framework to interfere with outbound email processing and potentially manipulate headers when applications send mail to user-supplied addresses. CVE-2026-48019 affects Laravel framework releases in the ranges < 12.60.0 and >= 13.0.0, < 13.10.0. Successful exploitation depends on an application sending email to attacker-controlled recipients and on how Symfony Mailer and Symfony Mime handle injected sequences.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.9HIGH
EPSS
0.00511
CWE
CWE-93
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: treat this as high priority because public exploit code is available; immediately restrict any ability to send mail to user-supplied addresses and apply vendor guidance or updates as soon as they are released.

What is CVE-2026-48019?

An unauthenticated attacker can exploit a CRLF injection flaw in the Laravel framework to interfere with outbound email processing and potentially manipulate headers when applications send mail to user-supplied addresses. CVE-2026-48019 affects Laravel framework releases in the ranges < 12.60.0 and >= 13.0.0, < 13.10.0. Successful exploitation depends on an application sending email to attacker-controlled recipients and on how Symfony Mailer and Symfony Mime handle injected sequences.

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

Which versions of laravel framework are affected?

BRANCHAFFECTEDFIXED
framework>= 13.0.0, < 13.10.0
framework< 12.60.0

Is CVE-2026-48019 being exploited?

Public exploit code is available.

How to fix CVE-2026-48019

  1. Prevent applications from sending email directly to user-supplied addresses or require a verified address before sending.
  2. Sanitize or reject input containing CRLF (\r or \n) characters used in addresses and headers.
  3. Harden mail sending: enforce server-side validation, use allowlists for recipient domains, and disable downstream features that auto-process untrusted headers.
  4. Monitor mail server and application logs for unusual header content, unexpected outbound messages, and signs of attempted header injection.

Frequently asked questions

Is CVE-2026-48019 being actively exploited?

Public exploit code is available for CVE-2026-48019.

Which framework versions are affected by CVE-2026-48019?

Laravel framework versions affected are those below 12.60.0 and versions >= 13.0.0 but < 13.10.0, per the vendor's affected ranges.

Is there a patch for CVE-2026-48019?

No vendor-fixed versions are listed in the supplied affected entries; as of 2026-09-29 a released patch is not indicated in the facts.

Does CVE-2026-48019 require authentication?

No — the vulnerability can be triggered by an unauthenticated attacker when an application sends mail to attacker-controlled addresses.

References