All findings

CVE-2026-45067 medium

Symfony credits Claude Mythos on SMTP command-injection CVE

Symfony credits Claude Mythos Preview via Project Glasswing for finding and helping fix a CRLF injection in Mime Address handling.

Bug class
Email header and SMTP command injection
Affected codebase
Symfony Mime
Credited system
Claude Mythos Preview
Disclosed
May 20, 2026
Attribution
Direct source attribution
Severity
medium
Source status: Symfony's upstream GHSA credits Claude Mythos Preview via Project Glasswing for reporting the issue and providing the fix. The advisory is Moderate and later received CVE-2026-45067.

Summary

Symfony’s Address handling failed to reject carriage-return and line-feed characters in a path that could reach generated email headers. Applications that accepted attacker-controlled addresses could be exposed to header or SMTP command injection.

Attribution

This is a direct upstream credit. Symfony names the model, the Project Glasswing route, the report, and the contributed fix.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.