Search
Find merged stories by title or summary.
cve-2026-77634
CakePHP: SmtpTransport vulnerable to CRLF header injection
CVE-2026-77634 - CakePHP: SmtpTransport vulnerable to CRLF header injection
CVE ID : CVE-2026-77634 Published : Aug. 24, 2026, 8:33 p. m. • 38 minutes ago Description : CakePHP is a rapid development framework for PHP. Prior to versions 4. 5. 12, 4. 6. 5, 5. 1. 8, 5. 2. 14, and 5. 3. 7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection when user-controlled data is used in message headers. This issue is fixed in versions 4. 5. 12, 4. 6. 5, 5. 1. 8, 5. 2. 14, and 5. 3. 7. Severity: 0.0 • NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
You've reached the end of current stories for this search.
