Vulnerability intelligence
CVE-2026-48019 — Laravel Vulnerability
CVE-2026-48019 allows email header manipulation via unsanitized CRLF sequences. A second CVE compounds the risk.
Laravel
2026
What WebPulse reported · 2 analyses
Laravel's Core Email Handling Has a CRLF Injection Flaw. It's Not a Plugin.
CVE-2026-48019 allows email header manipulation via unsanitized CRLF sequences. A second CVE compounds the risk.
June 21, 2026
Laravel Is the Best PHP Framework. It Still Got a High-Severity CVE This Week.
CVE-2026-48019 lets attackers inject headers into outbound emails — no authentication required. Laravel patched it in days. WordPress plugins with similar flaws
June 12, 2026
Related vulnerabilities