CVE-2026-45133
- EPSS 0.74%
- Veröffentlicht 14.07.2026 19:17:06
- Zuletzt bearbeitet 15.07.2026 14:54:50
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the...
CVE-2026-45070
- EPSS 0.29%
- Veröffentlicht 14.07.2026 19:17:06
- Zuletzt bearbeitet 16.07.2026 15:16:31
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits paramete...
CVE-2026-45069
- EPSS 0.24%
- Veröffentlicht 14.07.2026 19:17:06
- Zuletzt bearbeitet 15.07.2026 15:02:19
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pas...
CVE-2026-45064
- EPSS 0.29%
- Veröffentlicht 14.07.2026 19:17:05
- Zuletzt bearbeitet 21.07.2026 20:17:00
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanit...
CVE-2026-45063
- EPSS 0.33%
- Veröffentlicht 14.07.2026 19:17:05
- Zuletzt bearbeitet 15.07.2026 15:01:08
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex th...
CVE-2026-48747
- EPSS 0.2%
- Veröffentlicht 14.07.2026 19:16:24
- Zuletzt bearbeitet 15.07.2026 15:16:37
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed the request-selected ...
CVE-2026-48489
- EPSS 0.48%
- Veröffentlicht 14.07.2026 19:14:12
- Zuletzt bearbeitet 16.07.2026 15:16:31
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler honored the request-supplied _failure_path parameter when failure_forwa...
CVE-2026-48760
- EPSS 0.26%
- Veröffentlicht 14.07.2026 19:11:42
- Zuletzt bearbeitet 15.07.2026 15:16:37
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASC...
CVE-2026-48736
- EPSS 0.46%
- Veröffentlicht 14.07.2026 19:09:30
- Zuletzt bearbeitet 16.07.2026 03:12:24
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4,...
CVE-2026-48784
- EPSS 0.27%
- Veröffentlicht 14.07.2026 19:04:20
- Zuletzt bearbeitet 15.07.2026 14:44:46
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ seg...