CVEs we hold for Symfony
Records whose assigning authority named Symfony as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-55878Symfony: Path Traversal in symfony/ux-toolkit Allows Arbitrary File Write and Read via Crafted Recipe Manifestsymfony ux
CVE-2026-55877Symfony UX: XSS in symfony/ux-icons via unsanitized SVG content in local files and Iconify on-demand responsessymfony ux
CVE-2026-49215Symfony UX: CSRF Protection Bypass in symfony/ux-live-component — Accept Header is CORS-Safelistedsymfony ux
CVE-2026-49212Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot bindingsymfony ux
CVE-2026-49211Symfony UX: Information exposure via unescaped LIKE wildcards in EntitySearchUtilsymfony ux
CVE-2026-49210Symfony UX: XSS in symfony/ux-live-component via attacker-controlled child component tagsymfony ux
CVE-2026-49209Symfony UX: Denial of service in symfony/ux-live-component via unbounded batch action requestssymfony ux
CVE-2026-49208Symfony UX: Format-less date LiveProps parsed with the permissive DateTime constructorsymfony ux
CVE-2026-48784Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route…symfony; symfony routing
CVE-2026-48761Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL…symfony; symfony html-sanitizer
CVE-2026-48760Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass…symfony; symfony html-sanitizer
CVE-2026-48747Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgradesymfony; symfony mailomat-mailer
CVE-2026-48736Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in…symfony; symfony http-client; symfony http-foundation
CVE-2026-48489Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected…symfony; symfony security-http
CVE-2026-47767Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI…symfony; symfony runtime
CVE-2026-47212Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event…symfony; symfony twilio-notifier
CVE-2026-46644symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalencesymfony polyfill-intl-idn
CVE-2026-45756Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoSsymfony; symfony json-path
CVE-2026-45755Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injectionsymfony; /mailtrap-mailer mailtrap-mailer
CVE-2026-45754Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injectionsymfony; symfony lox24-notifier; symfony mailjet-mailer
CVE-2026-45753Symfony: HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — javascript: URI Survives…symfony; symfony html-sanitizer
CVE-2026-45305Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regexsymfony; symfony yaml
CVE-2026-45304Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")symfony; symfony yaml
CVE-2026-45077Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listenersymfony; symfony monolog-bridge
CVE-2026-45075Symfony: HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]symfony; symfony http-kernel; symfony security-http
CVE-2026-45074Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replaysymfony; symfony security-http
CVE-2026-45073Symfony: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefixsymfony; cache symfony
CVE-2026-45072Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Renderingsymfony; symfony twig-bridge; symfony web-profiler-bundle
CVE-2026-45071Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = truesymfony; symfony dom-crawler
CVE-2026-45070Symfony: Email Header Injection via Non-Token Characters in Mime Parameter Namessymfony; symfony mime
CVE-2026-45069Symfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claimssymfony; symfony security-http
CVE-2026-45068Symfony: Argument Injection in SendmailTransport via Dash-Prefixed Recipient Addresssymfony; symfony mailer
CVE-2026-45067Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Addresssymfony
CVE-2026-45066Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area>…symfony; symfony html-sanitizer
CVE-2026-45065Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injectionsymfony
CVE-2026-45064Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofingsymfony; symfony html-sanitizer
CVE-2026-24739Symfony has incorrect argument escaping under MSYS2/Git Bash on Windows that can lead to destructive file operationssymfony
CVE-2025-64500Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypasssymfony
CVE-2025-47946symfony/ux-live-component and symfony/ux-twig-component vulnerable to unsanitized HTML attribute injection via…symfony ux
CVE-2024-50343Incorrect response from Validator when input ends with `\n` in symfony/validatorsymfony
CVE-2024-50342Internal address and port enumeration allowed by NoPrivateNetworkHttpClient in symfony/http-clientsymfony
CVE-2024-50341Security::login does not take into account custom user_checker in symfony/security-bundlesymfony
CVE-2023-46734Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filterssymfony
CVE-2023-41336Prevent injection of invalid entity ids for "autocomplete" fields in symfony ux-autocompletesymfony ux-autocomplete
CVE-2020-5275Firewall configured with unanimous strategy was not actually unanimous in symfony/security-httpsymfony
65 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.