CVE-2017-14775: Laravel

Medium severity, CVSS 5.9. EPSS: 1.2% chance of exploitation in the next 30 days.

Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.

Affected products

  • Laravel Laravel: up to and including 5.5.9

Published 2017-09-28. Last modified 2026-06-17.