CVE-2025-27515: Laravel Framework

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1.

Affected products

  • Laravel Framework: before 11.44.1 (fixed in 11.44.1); from 12.0.0, before 12.1.1 (fixed in 12.1.1)

Published 2025-03-05. Last modified 2026-06-17.