Skip to content
RequestGuard Vulnerabilities
Pricing

symfony/http-client

Provides powerful methods to fetch HTTP resources synchronously or asynchronously

Composer latest 8.1.7 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

8.1.7

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Moderate

2 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

2

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

Affected range

ECOSYSTEM: introduced 5.4.0; fixed 5.4.53>=5.4.0,<5.4.53

Fixed versions: 5.4.53

Symfony allows internal address and port enumeration by NoPrivateNetworkHttpClient

Affected range

ECOSYSTEM: introduced 4.3.0; fixed 5.4.47ECOSYSTEM: introduced 6.0.0; fixed 6.4.15ECOSYSTEM: introduced 7.0.0; fixed 7.1.8>=4.3.0,<4.4.0|>=4.4.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.47|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.15|>=7.0.0,<7.1.0|>=7.1.0,<7.1.8

Fixed versions: 5.4.47, 6.4.15, 7.1.8