目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-61815— zbateson/mail-mime-parser CRLF头部注入漏洞

一分钟漏洞结论

影响对象
zbateson mail-mime-parser
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

zbateson/mail-mime-parser 是 PHP 中用于解析 MIME 邮件的替代方案,旨在替代原生的 imap* 函数及 PEAR 库,以支持按照 RFC 822 互联网邮件格式读取邮件。 在版本 3.0.6 和 4.0.2 之前,该库存在 CRLF(回车/换行符)头注入漏洞(CWE-93)。任何使用该库构建或转发 MIME 消息的应用程序,若使用了由攻击者控制的附件文件名,均会受到此漏洞影响。具体而言,附件文件名在插入到 和 头字段值时,未对 CR/LF 字符进行过滤或剥离。因此,若文件名中包含

CVSS 7.2 · High EPSS 0.18% · P7
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-61815 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
zbateson/mail-mime-parser has CRLF header injection via attachment filename
来源: CVE Program / CVE List V5
Vulnerability Description
zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to version 3.0.6 and 4.0.2, CRLF (carriage-return / line-feed) header injection (CWE-93) affecting any application that uses this library to build or forward MIME messages with an attacker-influenced attachment filename. Attachment filenames are interpolated into the `Content-Type` and `Content-Disposition` header values without stripping CR/LF, so a filename containing `\r\n` serializes as one or more additional, attacker-controlled header lines (for example a forged `Bcc:` that silently exfiltrates a copy of the outgoing message). The untrusted filename can come directly from parsed inbound mail, so no local construction is required — an application that re-attaches or re-sends a parsed filename is exposed. Versions 3.0.6 and 4.0.2 patch the issue. Versions 1.x and 2.x are also affected but are end-of-life and will not receive patches; users on those lines should upgrade to a fixed release. If upgrading is not immediately possible, strip CR and LF from any filename before passing it to attachment APIs, and from the result of getFilename() before reusing it in a constructed message — e.g. preg_replace('/[\r\n]+/', ' ', $filename).
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
对CRLF序列的转义处理不恰当(CRLF注入)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
zbateson mail-mime-parser < 3.0.6 -

二、漏洞 CVE-2026-61815 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-61815 的情报信息

请登录查看更多情报信息。

CVE-2026-61815 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-61815

暂无评论


发表评论