vciy

symfony: 22 records in one advisory

22 records announced together, published 2026-07-14, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://github.com/symfony/symfony/releases/tag/v8.0.12. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

Every record names something of its own, listed against it below.

Most commonly mapped weakness across the batch: CWE-290: Authentication Bypass by Spoofing.

What this page does not cover

This batch is 22 of the 23 records that cite the same advisory. The other 1 are different findings announced alongside it.

None of those 1 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2026-45063Symfony: Identity Spoofing via Unanchored DN Regex in X509AuthenticatorCWE-290: Authentication Bypass by Spoofing
CVE-2026-45064Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href SpoofingCWE-451: User Interface (UI) Misrepresentation…
CVE-2026-45065Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL InjectionCWE-185: Incorrect Regular Expression
CVE-2026-45066Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area>…CWE-184: Incomplete List of Disallowed Inputs
CVE-2026-45068Symfony: Argument Injection in SendmailTransport via Dash-Prefixed Recipient AddressCWE-88: Improper Neutralization of Argument…
CVE-2026-45069Symfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp ClaimsCWE-345: Insufficient Verification of Data…
CVE-2026-45070Symfony: Email Header Injection via Non-Token Characters in Mime Parameter NamesCWE-93: Improper Neutralization of CRLF…
CVE-2026-45071Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = trueCWE-611: Improper Restriction of XML External…
CVE-2026-45072Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File RenderingCWE-79: Improper Neutralization of Input During…
CVE-2026-45073Symfony: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefixCWE-89: Improper Neutralization of Special…
CVE-2026-45074Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket ReplayCWE-290: Authentication Bypass by Spoofing
CVE-2026-45075Symfony: HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]CWE-863: Incorrect Authorization
CVE-2026-45077Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log ListenerCWE-502: Deserialization of Untrusted Data
CVE-2026-45133Symfony: [Yaml] Harden the parser when handling untrusted inputCWE-674: Uncontrolled Recursion
CVE-2026-45304Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")CWE-776: Improper Restriction of Recursive…
CVE-2026-45305Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() RegexCWE-1333: Inefficient Regular Expression…
CVE-2026-45753Symfony: HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — javascript: URI Survives…CWE-79: Improper Neutralization of Input During…
CVE-2026-45754Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event InjectionCWE-287: Improper Authentication
CVE-2026-45755Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event InjectionCWE-306: Missing Authentication for Critical…
CVE-2026-45756Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoSCWE-400: Uncontrolled Resource Consumption
CVE-2026-47212Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event…CWE-306: Missing Authentication for Critical…
CVE-2026-47767Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI…CWE-436: Interpretation Conflict

22 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.