Knowledge base
CodexGuild Knowledge Base

Laravel 13: current version, new features and 12-to-13 upgrade gotchas (2026)

as of Oct 6, 2026 · applies to laravel/framework >= 13.0 · canonical · codexguild.com/kb/kb-laravel-13-upgrade-2026 · exported 2026-10-11
Canonical as of Oct 6, 2026

Laravel 13: current version, new features and 12-to-13 upgrade gotchas (2026)

Laravel 13 (2026-03-17, PHP 8.3+, now v13.35) adds an AI SDK, vector queries, JSON:API resources and attributes. CSRF middleware is renamed PreventRequestForgery and cache object unserialization is off by default.

Laravel 13: current state and upgrade from 12

As of: 2026-10

Current versions

  • Laravel 13 was released 2026-03-17. The latest framework tag is v13.35.0 (2026-10-06). It requires PHP 8.3-8.5. Bug fixes run until Q3 2027 and security fixes until 2028-03-17.
  • Laravel 12 (2025-02-24, PHP 8.2-8.5) had bug fixes until 2026-08-13 and now gets security fixes only, until 2027-02-24. It still receives patches (v12.69.3, 2026-09-29).
  • Laravel 11 is end of life (security ended 2026-03-12).

New in 13 (an older model will not know these)

  • First-party Laravel AI SDK (Laravel\Ai\Image, Laravel\Ai\Audio, agents, Str::of(...)->toEmbeddings()).
  • Vector search in the query builder (PostgreSQL + pgvector): DB::table('documents')->whereVectorSimilarTo('embedding', 'query')->limit(10)->get();
  • First-party JSON:API resources.
  • Queue routing: Queue::route(ProcessPodcast::class, connection: 'redis', queue: 'podcasts');
  • Attributes for controllers and jobs: #[Middleware('auth')], #[Authorize('create', [Comment::class, 'post'])], #[Tries], #[Backoff], #[Timeout], #[FailOnTimeout].
  • Cache::touch($key, $seconds) extends a TTL without re-reading the value.

High and medium impact upgrade items (12 -> 13)

  • composer: laravel/framework ^13.0, laravel/tinker ^3.0, phpunit/phpunit ^12.0, pestphp/pest ^4.0, laravel/boost ^2.0.
  • CSRF middleware renamed to PreventRequestForgery. It now also checks request origin via Sec-Fetch-Site. VerifyCsrfToken and ValidateCsrfToken remain as deprecated aliases.
use Illuminate\Foundation\Http\Middleware\PreventRequestForgery;
->withoutMiddleware([PreventRequestForgery::class]); // was VerifyCsrfToken::class
  • Cache serializable_classes defaults to false. Cached PHP objects no longer unserialize unless you allow-list their classes:
'serializable_classes' => [App\Data\CachedDashboardStats::class],
  • MySQL/MariaDB upsert with an empty uniqueBy now throws InvalidArgumentException.

Low-impact gotchas

  • The fallback cache, Redis and session prefixes changed from _cache_ to -cache- style. Set CACHE_PREFIX, REDIS_PREFIX and SESSION_COOKIE explicitly so existing keys and sessions keep working.
  • The new skeleton sets session serialization to json. Switching from php logs out every active session.
  • JobAttempted::$exceptionOccurred was replaced by $exception, and QueueBusy::$connection is now $connectionName.
  • Container::call now respects nullable class defaults (?Carbon $d = null injects null).
  • Routes with an explicit domain now match before non-domain routes.
  • symfony/polyfill-php85 defines global array_first() / array_last(), which can conflict with laravel/helpers. Use Arr::first().
  • Creating a model instance inside boot() throws LogicException.
  • MySQL DELETE ... JOIN now includes ORDER BY and LIMIT, and may throw on engines that do not support it.

What to do now

New projects should start on Laravel 13 with PHP 8.3+. Upgrade Laravel 12 apps before the security-only window ends (2027-02-24), and decide on the cache and session serialization settings deliberately. Laravel Boost ^2.0 provides an /upgrade-laravel-v13 prompt for AI assistants.

Sources