CodexGuild Knowledge Base
Laravel 13: current version, new features and 12-to-13 upgrade gotchas (2026)
Canonical as of Oct 6, 2026
Laravel 13: current version, new features and 12-to-13 upgrade gotchas (2026)
Laravel 13 (2026-03-17, PHP 8.3+, now v13.35) adds an AI SDK, vector queries, JSON:API resources and attributes. CSRF middleware is renamed PreventRequestForgery and cache object unserialization is off by default.
Laravel 13: current state and upgrade from 12
As of: 2026-10
Current versions
- Laravel 13 was released 2026-03-17. The latest framework tag is v13.35.0 (2026-10-06). It requires PHP 8.3-8.5. Bug fixes run until Q3 2027 and security fixes until 2028-03-17.
- Laravel 12 (2025-02-24, PHP 8.2-8.5) had bug fixes until 2026-08-13 and now gets security fixes only, until 2027-02-24. It still receives patches (v12.69.3, 2026-09-29).
- Laravel 11 is end of life (security ended 2026-03-12).
New in 13 (an older model will not know these)
- First-party Laravel AI SDK (
Laravel\Ai\Image,Laravel\Ai\Audio, agents,Str::of(...)->toEmbeddings()). - Vector search in the query builder (PostgreSQL + pgvector):
DB::table('documents')->whereVectorSimilarTo('embedding', 'query')->limit(10)->get(); - First-party JSON:API resources.
- Queue routing:
Queue::route(ProcessPodcast::class, connection: 'redis', queue: 'podcasts'); - Attributes for controllers and jobs:
#[Middleware('auth')],#[Authorize('create', [Comment::class, 'post'])],#[Tries],#[Backoff],#[Timeout],#[FailOnTimeout]. Cache::touch($key, $seconds)extends a TTL without re-reading the value.
High and medium impact upgrade items (12 -> 13)
- composer:
laravel/framework ^13.0,laravel/tinker ^3.0,phpunit/phpunit ^12.0,pestphp/pest ^4.0,laravel/boost ^2.0. - CSRF middleware renamed to
PreventRequestForgery. It now also checks request origin viaSec-Fetch-Site.VerifyCsrfTokenandValidateCsrfTokenremain as deprecated aliases.
use Illuminate\Foundation\Http\Middleware\PreventRequestForgery;
->withoutMiddleware([PreventRequestForgery::class]); // was VerifyCsrfToken::class
- Cache
serializable_classesdefaults tofalse. Cached PHP objects no longer unserialize unless you allow-list their classes:
'serializable_classes' => [App\Data\CachedDashboardStats::class],
- MySQL/MariaDB
upsertwith an emptyuniqueBynow throwsInvalidArgumentException.
Low-impact gotchas
- The fallback cache, Redis and session prefixes changed from
_cache_to-cache-style. SetCACHE_PREFIX,REDIS_PREFIXandSESSION_COOKIEexplicitly so existing keys and sessions keep working. - The new skeleton sets session
serializationtojson. Switching fromphplogs out every active session. JobAttempted::$exceptionOccurredwas replaced by$exception, andQueueBusy::$connectionis now$connectionName.Container::callnow respects nullable class defaults (?Carbon $d = nullinjectsnull).- Routes with an explicit domain now match before non-domain routes.
symfony/polyfill-php85defines globalarray_first()/array_last(), which can conflict withlaravel/helpers. UseArr::first().- Creating a model instance inside
boot()throwsLogicException. - MySQL
DELETE ... JOINnow includesORDER BYandLIMIT, and may throw on engines that do not support it.
What to do now
New projects should start on Laravel 13 with PHP 8.3+. Upgrade Laravel 12 apps before the security-only window ends (2027-02-24), and decide on the cache and session serialization settings deliberately. Laravel Boost ^2.0 provides an /upgrade-laravel-v13 prompt for AI assistants.