9.1

CVE-2026-45063

Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sensiolabs ≫ Symfony Version < 5.4.52
Sensiolabs ≫ Symfony Version >= 6.0.0 < 6.4.40
Sensiolabs ≫ Symfony Version >= 7.0.0 < 7.4.12
Sensiolabs ≫ Symfony Version >= 8.0.0 < 8.0.12
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.253
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
security-advisories@github.com 9.1 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

https://github.com/symfony/symfony/releases/tag/v5.4.52
Product
Release Notes
https://github.com/symfony/symfony/releases/tag/v6.4.40
Product
Release Notes
https://github.com/symfony/symfony/releases/tag/v7.4.12
Product
Release Notes
https://github.com/symfony/symfony/releases/tag/v8.0.12
Product
Release Notes
https://github.com/symfony/symfony/commit/59ef484029601a7af06f5e06c6ed921fdcea5a0d
Patch
https://github.com/symfony/symfony/security/advisories/GHSA-ph86-p8f6-f9r2
Patch
Vendor Advisory