highVulnerability

CVE-2026-77634

### Impact Custom mail headers added with `Message::setHeaders()` or `addHeaders()` do not have CRLF replaced allowing header injection if user controlled data is added to message headers without stripping CRLF bytes. ### Patches 5.3.7, 5.2.14, 5.1.9, 4.6.5, 4.5.12 contain fixes for this issue. ### Workarounds You can strip CRLF bytes from email header values before setting header values.

Properties

ghsa_id
GHSA-2qh5-382h-3jpc
summary
CakePHP: SmtpTransport vulnerable to CRLF header injection
severity
high
epss_score
0.00312
cve_id
CVE-2026-77634
is_ghsa_only
false
ghsa_published
2026-09-08T20:56:26Z
source_url
https://github.com/advisories/GHSA-2qh5-382h-3jpc
epss_percentile
0.23747
ghsa_updated
2026-09-08T20:56:26Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/cakephp/cakephp

AFFECTS (1)

[Software]composer/cakephp/cakephp

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of CRLF Sequences ('CRLF Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77634 — Ninja Signal Threat Intelligence | Ninja Signal