๐Ÿ” CVE Alert

CVE-2026-77634

UNKNOWN 0.0

CakePHP: SmtpTransport vulnerable to CRLF header injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection when user-controlled data is used in message headers. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7.

CWE CWE-93
Vendor cakephp
Product cakephp
Published Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for cakephp cakephp

Be the first to know when new unknown vulnerabilities affecting cakephp cakephp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

cakephp / cakephp
>= 4.5.0, < 4.5.12 >= 4.6.0, < 4.6.5 >= 5.0.0, < 5.1.9 >= 5.2.0, < 5.2.14 >= 5.3.0, < 5.3.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cakephp/cakephp/security/advisories/GHSA-2qh5-382h-3jpc github.com: https://github.com/cakephp/cakephp/commit/08188962bcd99a95da1e49f62e786f2d688f1e41 github.com: https://github.com/cakephp/cakephp/commit/2afe42b02d8ddc5d442bca5e8bb61910a727646e github.com: https://github.com/cakephp/cakephp/commit/3e09dae6cbdc983754fa3a8e6aae74da102a3ea1 github.com: https://github.com/cakephp/cakephp/commit/b67b622457362b075bb37e625a82af73a0b3c9c3