[CRLF injection in default email rule]
https://github.com/laravel/framework/security/advisories/GHSA-5vg9-5847-vvmq