CVE-2026-77634 | CakePHP up to 5.3.6 Message Message::setHeaders crlf injection
A vulnerability described as critical has been identified in CakePHP up to 4.5.11/4.6.4/5.1.7/5.2.13/5.3.6. This vulnerability affects the function Message::setHeaders of the component Message. Such manipulation leads to crlf injection.
This vulnerability is documented as CVE-2026-77634. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More