8.6

CVE-2026-48736

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sensiolabs ≫ Symfony Version >= 5.4.0 < 5.4.43
Sensiolabs ≫ Symfony Version >= 6.4.0 < 6.4.41
Sensiolabs ≫ Symfony Version >= 7.0.0 < 7.4.13
Sensiolabs ≫ Symfony Version >= 8.0.0 < 8.0.13
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.37
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
security-advisories@github.com 6.9 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-184 Incomplete List of Disallowed Inputs

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

https://github.com/symfony/symfony/releases/tag/v5.4.53
Release Notes
https://github.com/symfony/symfony/releases/tag/v6.4.41
Release Notes
https://github.com/symfony/symfony/releases/tag/v7.4.13
Release Notes
https://github.com/symfony/symfony/security/advisories/GHSA-38cx-cq6f-5755
Patch
Vendor Advisory
https://github.com/symfony/symfony/commit/82765368cf74177c36613575182f168a2eb765b2
Patch
https://github.com/symfony/symfony/commit/85b831555be8ea1f43bf01078afe87bc4c92f65e
Patch