CVE-2025-27515

Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
GitHub_MCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
VendorProductVersion
laravelframework
𝑥
< 11.44.1
laravelframework
12.0.0 ≤
𝑥
< 12.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
php-laravel-framework
bullseye
vulnerable
bullseye (security)
vulnerable
bookworm
vulnerable
forky
10.48.29+dfsg-1
fixed
sid
10.48.29+dfsg-1
fixed
trixie
10.48.29+dfsg-1
fixed