CVE-2026-61815 | zbateson mail-mime-parser up to 3.0.5/4.0.1 Attachment Filename getFilename filename crlf injection

SecurityVulns

A vulnerability described as critical has been identified in zbateson mail-mime-parser up to 3.0.5/4.0.1. Affected is the function getFilename of the component Attachment Filename Handler. Such manipulation of the argument filename leads to crlf injection.

This vulnerability is traded as CVE-2026-61815. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More