Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1.
References
Configurations
Configuration 1 (hide)
|
History
26 Aug 2025, 17:13
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Laravel framework
Laravel |
|
CPE | cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:* | |
References | () https://github.com/laravel/framework/commit/2d133034fefddfb047838f4caca3687a3ba811a5 - Patch | |
References | () https://github.com/laravel/framework/security/advisories/GHSA-78fx-h6xr-vch4 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
05 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-05 19:15
Updated : 2025-08-26 17:13
NVD link : CVE-2025-27515
Mitre link : CVE-2025-27515
CVE.ORG link : CVE-2025-27515
JSON object : View
Products Affected
laravel
- framework
CWE
CWE-155
Improper Neutralization of Wildcards or Matching Symbols