Laravel 13.30.0 and 12.69.0 fix CVE-2026-102279, a low-severity debug page XSS, and also contain the fixes for the 8.9-rated email CRLF flaw and the signed URL flaw.
Composer 2.10.2 refused to resolve five of the seven affected versions I tried, but an existing composer.lock still installs them, so run composer audit --locked in CI.
Fixes shipped 22 to 29 days before the GitHub advisories, and NVD listed the CRLF CVE 108 days after its fix, which explains conflicting dates online.