CVE-2026-77634High▾ TwilightCakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection when user-controlled data is used in message headers. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
cakephp/cakephp >= 4.5.0, < 4.5.12cakephp/cakephp >= 4.6.0, < 4.6.5cakephp/cakephp >= 5.0.0, < 5.1.8cakephp/cakephp >= 5.2.0, < 5.2.14cakephp/cakephp >= 5.3.0, < 5.3.7Patched in:
cakephp/cakephp 4.5.12cakephp/cakephp 4.6.5cakephp/cakephp 5.1.9cakephp/cakephp 5.2.14cakephp/cakephp 5.3.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77635CriticalCakePHP is a rapid development framework for PHP
CVE-2026-48820MediumCakePHP: View::element() is missing a path containment check
CVE-2026-79752Critical· 9.2CakePHP is a rapid development framework for PHP
CVE-2026-54713Low· 3.7CakePHP Queue is a queue-interop compatible queueing library
CVE-2026-54614Medium· 4.3DebugKit provides a debugging toolbar for CakePHP applications
CVE-2026-55590MediumCakePHP Authentication: Open redirect weakness via backslash bypass