End of life / Laravel / 5.5
Laravel 5.5 end of life
Laravel 5.5 reached end of life on 30 August 2020, 2,198 days ago. 18 known CVEs reach this release, the most severe rated CRITICAL.
The detail
- Released
- 30 August 2017
- End of life
- 30 August 2020
- Countdown
- 2,198 days ago
- Status
- End of life
- Long term support
- Yes
- Newest build on this release
- 5.5.50
- Newest release overall
- 13.30.1
CVEs that reach 5.5
| Advisory | Severity | CVSS | Published | Fixed in |
|---|---|---|---|---|
| GHSA-qm5c-m76r-2hfr Laravel RCE vulnerability in "cookie" session driver | CRITICAL | 9.9 | 15 May 2024 | 6.18.31 |
| GHSA-5vg9-5847-vvmq Laravel Framework: CRLF injection in default email rule | HIGH | 8.9 | 17 June 2026 | 12.60.0 |
| CVE-2020-19316 OS Command Injection in Laravel Framework | HIGH | 8.8 | 6 January 2022 | 5.8.17 |
| CVE-2024-52301 Laravel environment manipulation via query string | HIGH | 8.7 | 12 November 2024 | 6.20.45 |
| CVE-2018-15133 In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a pre | HIGH | 8.1 | 9 August 2018 | no fixed version published |
| CVE-2020-24941 An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions. | HIGH | 7.5 | 4 September 2020 | 6.18.35 |
| CVE-2020-24940 An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment. | HIGH | 7.5 | 4 September 2020 | 6.18.34 |
| CVE-2017-16894 In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework. | HIGH | 7.5 | 20 November 2017 | no fixed version published |
| GHSA-x7p5-p2c9-phvg Unexpected database bindings | HIGH | 7.2 | 2 February 2021 | 6.20.14 |
| GHSA-6jvx-8ch9-j2jr Laravel Cookie serialization vulnerability | HIGH | - | 15 May 2024 | 5.6.30 |
| GHSA-4mg9-vhxq-vm7j SQL Server LIMIT / OFFSET SQL Injection in laravel/framework and illuminate/database | HIGH | - | 29 April 2021 | 6.20.26 |
| CVE-2025-27515 Laravel has a File Validation Bypass | MEDIUM | 6.9 | 5 March 2025 | 10.48.29 |
| CVE-2021-43808 Laravel Framework XSS in Blade templating engine | MEDIUM | 6.1 | 8 December 2021 | 6.20.42 |
| CVE-2017-14775 Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison. | MEDIUM | 5.9 | 28 September 2017 | 5.5.10 |
| GHSA-crmm-hgp2-wgrp Laravel Framework: Temporary Signed URL Path Confusion | MEDIUM | 4.2 | 17 June 2026 | 12.61.1 |
| GHSA-44pg-c29v-hp6r Laravel Guard bypass in Eloquent models | MEDIUM | - | 15 May 2024 | no fixed version published |
| GHSA-7852-w36x-6mf6 Laravel Encrypter Component Potential Decryption Failure Leading to Unintended Behavior | MEDIUM | - | 15 May 2024 | 5.5.40 |
| CVE-2021-43617 Withdrawn: Laravel Framework does not sufficiently block the upload of executable PHP content. | MEDIUM | - | 16 November 2021 | no fixed version published |
Where to move next
The newest tracked release is 13.30.1. If moving release is not an option yet, 5.5.50 is the newest build on the 5.5 line and needs no migration.
Other Laravel releases
Vendor sources last checked 6 September 2026, and checked daily. This data last changed on 6 September 2026.
You just looked this up by hand, for one version
StackDrift scans your machines, works out every version you actually run, and mails you before the next support window closes or a CVE lands on a build you have deployed. It covers the runtimes, operating systems and kernels underneath your code, not just your packages.