Source status: Symfony's upstream GHSA credits Claude Mythos Preview via Project Glasswing for reporting the issue and providing the fix. The advisory is Moderate and later received CVE-2026-45067.
Summary
Symfony’s Address handling failed to reject carriage-return and line-feed
characters in a path that could reach generated email headers. Applications
that accepted attacker-controlled addresses could be exposed to header or SMTP
command injection.
Attribution
This is a direct upstream credit. Symfony names the model, the Project Glasswing route, the report, and the contributed fix.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.