Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-61815— zbateson/mail-mime-parser has CRLF header injection via attachment filename

Quick assessment

Affected
zbateson mail-mime-parser
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

zbateson/mail-mime-parser 是 PHP 中用于解析 MIME 邮件的替代方案,旨在替代原生的 imap* 函数及 PEAR 库,以支持按照 RFC 822 互联网邮件格式读取邮件。 在版本 3.0.6 和 4.0.2 之前,该库存在 CRLF(回车/换行符)头注入漏洞(CWE-93)。任何使用该库构建或转发 MIME 消息的应用程序,若使用了由攻击者控制的附件文件名,均会受到此漏洞影响。具体而言,附件文件名在插入到 和 头字段值时,未对 CR/LF 字符进行过滤或剥离。因此,若文件名中包含

CVSS 7.2 · High EPSS 0.18% · P7
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61815

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
zbateson/mail-mime-parser has CRLF header injection via attachment filename
Source: CVE Program / CVE List V5
Vulnerability Description
zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to version 3.0.6 and 4.0.2, CRLF (carriage-return / line-feed) header injection (CWE-93) affecting any application that uses this library to build or forward MIME messages with an attacker-influenced attachment filename. Attachment filenames are interpolated into the `Content-Type` and `Content-Disposition` header values without stripping CR/LF, so a filename containing `\r\n` serializes as one or more additional, attacker-controlled header lines (for example a forged `Bcc:` that silently exfiltrates a copy of the outgoing message). The untrusted filename can come directly from parsed inbound mail, so no local construction is required — an application that re-attaches or re-sends a parsed filename is exposed. Versions 3.0.6 and 4.0.2 patch the issue. Versions 1.x and 2.x are also affected but are end-of-life and will not receive patches; users on those lines should upgrade to a fixed release. If upgrading is not immediately possible, strip CR and LF from any filename before passing it to attachment APIs, and from the result of getFilename() before reusing it in a constructed message — e.g. preg_replace('/[\r\n]+/', ' ', $filename).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对CRLF序列的转义处理不恰当(CRLF注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zbateson mail-mime-parser < 3.0.6 -

II. Public POCs for CVE-2026-61815

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61815

请登录查看更多情报信息。

Other References for CVE-2026-61815 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-61815

No comments yet


Leave a comment