Security: symfony/symfony
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 NormalizationGHSA-h5x3-xfc9-m39h published
May 27, 2026 by fabpotModerate -
HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> contentGHSA-x5qj-865h-mgvm published
May 27, 2026 by fabpotModerate -
HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing DefenseGHSA-v3wm-qf9p-c549 published
May 27, 2026 by fabpotModerate -
Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm DowngradeGHSA-rrj9-5q2j-4gvr published
May 27, 2026 by fabpotModerate -
IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClientGHSA-38cx-cq6f-5755 published
May 27, 2026 by fabpotModerate -
Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET RoutesGHSA-6h46-9jf5-q59x published
May 27, 2026 by fabpotHigh -
SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv MismatchGHSA-fqc7-9xjw-jrh3 published
May 20, 2026 by nicolas-grekasHigh -
Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event InjectionGHSA-55rj-x2vc-4whq published
May 20, 2026 by nicolas-grekasModerate -
JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits: ReDoSGHSA-8v8v-g73j-492j published
May 20, 2026 by nicolas-grekasModerate -
Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC: Unauthenticated Webhook Event InjectionGHSA-59f3-vp2f-mp9w published
May 20, 2026 by nicolas-grekasModerate