{"id":"GHSA-f57v-q966-7fh6","summary":"Monolog Header injection in NativeMailerHandler","details":"A header injection vulnerability has been identified in the NativeMailerHandler of the Monolog library. This vulnerability may allow an attacker to manipulate email headers when log messages are sent via email.","modified":"2024-11-29T05:40:52.145864Z","published":"2024-05-15T23:08:13Z","database_specific":{"github_reviewed_at":"2024-05-15T23:08:13Z","nvd_published_at":null,"cwe_ids":["CWE-74"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/Seldaek/monolog/issues/458"},{"type":"WEB","url":"https://github.com/Seldaek/monolog/pull/448#issuecomment-68208704"},{"type":"WEB","url":"https://github.com/Seldaek/monolog/commit/515a096c864b00b3967f7f601680f85d4a2e4001"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/monolog/monolog/2014-12-29-1.yaml"},{"type":"PACKAGE","url":"https://github.com/Seldaek/monolog"}],"affected":[{"package":{"name":"monolog/monolog","ecosystem":"Packagist","purl":"pkg:composer/monolog/monolog"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.8.0"},{"fixed":"1.12.0"}]}],"versions":["1.10.0","1.11.0","1.8.0","1.9.0","1.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-f57v-q966-7fh6/GHSA-f57v-q966-7fh6.json"}}],"schema_version":"1.9.0"}