Laravel CVE-2026-102279: Which Version Fixes It?

Laravel 13.30.0 and 12.69.0 fix CVE-2026-102279, a low-severity debug page XSS, and also contain the fixes for the 8.9-rated email CRLF flaw and the signed URL flaw.

Composer 2.10.2 refused to resolve five of the seven affected versions I tried, but an existing composer.lock still installs them, so run composer audit --locked in CI.

Fixes shipped 22 to 29 days before the GitHub advisories, and NVD listed the CRLF CVE 108 days after its fix, which explains conflicting dates online.

Read the full post

Read the full post