CVE-2026-77634
Severity CVSS v4.0:
HIGH
Type:
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
Publication date:
24/08/2026
Last modified:
25/08/2026
Description
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection when user-controlled data is used in message headers. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7.
Impact
Base Score 4.0
8.20
Severity 4.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/cakephp/cakephp/commit/08188962bcd99a95da1e49f62e786f2d688f1e41
- https://github.com/cakephp/cakephp/commit/2afe42b02d8ddc5d442bca5e8bb61910a727646e
- https://github.com/cakephp/cakephp/commit/3e09dae6cbdc983754fa3a8e6aae74da102a3ea1
- https://github.com/cakephp/cakephp/commit/b67b622457362b075bb37e625a82af73a0b3c9c3
- https://github.com/cakephp/cakephp/security/advisories/GHSA-2qh5-382h-3jpc



