Skip to content
RequestGuard Vulnerabilities
Pricing

symfony/cache

Provides extended PSR-6, PSR-16 (and tags) implementations

Composer latest 8.1.7 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

8.1.7

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

3 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

3

Symfony Unsafe Cache Serialization Could Enable RCE

Affected range

ECOSYSTEM: introduced 3.1.0; fixed 3.4.35ECOSYSTEM: introduced 4.0.0; fixed 4.2.12ECOSYSTEM: introduced 4.3.0; fixed 4.3.8>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.35|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.2.12|>=4.3.0,<4.3.8

Fixed versions: 3.4.35, 4.2.12, 4.3.8

Deserialization of untrusted data in Symfony

Affected range

ECOSYSTEM: introduced 3.1.0; fixed 3.4.26ECOSYSTEM: introduced 4.0.0; fixed 4.1.12ECOSYSTEM: introduced 4.2.0; fixed 4.2.7>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.26|>=4.0.0,<4.1.0|>=4.1.0,<4.1.12|>=4.2.0,<4.2.7

Fixed versions: 3.4.26, 4.1.12, 4.2.7

Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix

Affected range

ECOSYSTEM: introduced 0; fixed 5.4.52ECOSYSTEM: introduced 6.0.0; fixed 6.4.40ECOSYSTEM: introduced 7.0.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12

Fixed versions: 5.4.52, 6.4.40, 7.4.12, 8.0.12