laravel/framework Security Advisories for v9.34.0 (5)
-
[MEDIUM] Laravel Framework: Temporary Signed URL Path Confusion
PKSA-m5cs-t1y6-qpcs GHSA-crmm-hgp2-wgrp
Affected version: <12.61.1|>=13.0.0,<13.12.0
Reported by:
GitHub -
[HIGH] Laravel Framework: CRLF injection in default email rule
PKSA-3r5d-mb8f-1qw9 GHSA-5vg9-5847-vvmq
Affected version: <12.60.0|>=13.0.0,<=13.9.0
Reported by:
GitHub -
Laravel CRLF injection in default email rule
PKSA-mdq4-51ck-6kdq CVE-2026-48019
Affected version: >=9.0.0,<10.0.0|>=10.0.0,<11.0.0|>=11.0.0,<12.0.0|>=12.0.0,<12.60.0|>=13.0.0,<13.10.0
Reported by:
FriendsOfPHP/security-advisories -
[MEDIUM] Laravel has a File Validation Bypass
PKSA-8qx3-n5y5-vvnd CVE-2025-27515 GHSA-78fx-h6xr-vch4
Affected version: <10.48.29|>=11.0.0,<11.44.1|>=12.0.0,<12.1.1
Reported by:
GitHub -
[HIGH] Laravel environment manipulation via query string
PKSA-w7xr-vk7n-rstm CVE-2024-52301 GHSA-gv7v-rgg6-548h
Affected version: <6.20.45|>=7.0.0,<7.30.7|>=8.0.0,<8.83.28|>=9.0.0,<9.52.17|>=10.0.0,<10.48.23|>=11.0.0,<11.31.0
Reported by:
GitHub, FriendsOfPHP/security-advisories