DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-61815: CVE-2026-61815: Remote SMTP Header Injection via Unsanitized MIME Decoded Filenames in zbateson/mail-mime-parser

CVE-2026-61815: Remote SMTP Header Injection via Unsanitized MIME Decoded Filenames in zbateson/mail-mime-parser

Vulnerability ID: CVE-2026-61815
CVSS Score: 7.2
Published: 2026-09-24

CVE-2026-61815 is a high-severity Carriage Return / Line Feed (CRLF) header injection vulnerability in the zbateson/mail-mime-parser library. Due to incomplete sanitization logic, encoded newline sequences within filenames and headers survive parsing and translate into literal CRLF control bytes. When applications process or forward these payloads, the library writes the unescaped control bytes directly into outbound SMTP metadata, allowing remote attackers to inject rogue headers or compromise message integrity.

TL;DR

A validation error in zbateson/mail-mime-parser allows remote attackers to inject malicious email headers (such as Bcc directives) by embedding encoded CRLF sequences inside attachment filenames. Patches in versions 3.0.6 and 4.0.2 remediate the issue.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-93
  • Attack Vector: Network (Remote)
  • CVSS v3.1 Score: 7.2
  • Impact Type: Header Injection / Email Exfiltration
  • Exploit Status: Proof-of-Concept
  • CISA KEV Listed: No

Affected Systems

  • zbateson/mail-mime-parser < 3.0.6
  • zbateson/mail-mime-parser >= 4.0.0, < 4.0.2
  • zbateson/mail-mime-parser 1.x (all versions, End-of-Life)
  • zbateson/mail-mime-parser 2.x (all versions, End-of-Life)
  • mail-mime-parser: < 3.0.6 (Fixed in: 3.0.6)
  • mail-mime-parser: >= 4.0.0, < 4.0.2 (Fixed in: 4.0.2)

Code Analysis

Commit: 81859c0

Fix CRLF injection vulnerabilities on the 4.x branch.

Commit: d2970b5

Fix CRLF injection vulnerabilities on the 3.x branch.

Mitigation Strategies

  • Upgrade zbateson/mail-mime-parser to 3.0.6, 3.0.7, or 4.0.2 to establish post-decode input validation.
  • Apply localized sanitization on filenames using standard regular expressions prior to passing variables to attachment-handling helper classes.
  • Disable automatic email forwarding or autoresponder mechanisms for attachments derived from untrusted inbound files.

Remediation Steps:

  1. Identify the current library version in composer.json under zbateson/mail-mime-parser.
  2. Run 'composer update zbateson/mail-mime-parser' to download and link the patched release.
  3. Audit all custom attachment handlers and introduce structural checks on email attributes.
  4. Validate mail transfer agent (MTA) logs for anomalous headers or unauthorized outbound BCC routing.

References


Read the full report for CVE-2026-61815 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)