Skip to content
RequestGuard Vulnerabilities
Pricing

symfony/http-kernel

Provides a structured process for converting a Request into a Response

Composer latest 8.1.7 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

8.1.7

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

High

8 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

8

Symfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]

Affected range

ECOSYSTEM: introduced 7.4.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=7.4.0,<7.4.12|>=8.0.0,<8.0.12

Fixed versions: 7.4.12, 8.0.12

RCE in Symfony

Affected range

ECOSYSTEM: introduced 4.3.0; fixed 4.4.13ECOSYSTEM: introduced 5.0.0; fixed 5.1.5>=4.3.0,<4.4.0|>=4.4.0,<4.4.13|>=5.0.0,<5.1.0|>=5.1.0,<5.1.5

Fixed versions: 4.4.13, 5.1.5

Symfony allows direct access of ESI URLs behind a trusted proxy

Affected range

ECOSYSTEM: introduced 2.0.0; fixed 2.3.19ECOSYSTEM: introduced 2.4.0; fixed 2.4.9ECOSYSTEM: introduced 2.5.0; fixed 2.5.4>=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.3.19|>=2.4.0,<2.4.9|>=2.5.0,<2.5.4

Fixed versions: 2.3.19, 2.4.9, 2.5.4

Symfony Http-Kernel has non-constant time comparison in UriSigner

Affected range

ECOSYSTEM: introduced 2.2.0; fixed 2.8.52ECOSYSTEM: introduced 3.0.0; fixed 3.4.35ECOSYSTEM: introduced 4.0.0; fixed 4.2.12ECOSYSTEM: introduced 4.3.0; fixed 4.3.8>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.8.0|>=2.8.0,<2.8.52|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.35|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.2.12|>=4.3.0,<4.3.8

Fixed versions: 2.8.52, 3.4.35, 4.2.12, 4.3.8

Symfony storing cookie headers in HttpCache

Affected range

ECOSYSTEM: introduced 2.0.0; fixed 4.4.50ECOSYSTEM: introduced 5.0.0; fixed 5.4.20ECOSYSTEM: introduced 6.0.0; fixed 6.0.20ECOSYSTEM: introduced 6.1.0; fixed 6.1.12ECOSYSTEM: introduced 6.2.0; fixed 6.2.6

Fixed versions: 4.4.50, 5.4.20, 6.0.20, 6.1.12, 6.2.6

Symfony Vulnerable to PHP Eval Injection

Affected range

ECOSYSTEM: introduced 2.0.0; fixed 2.3.27ECOSYSTEM: introduced 2.4.0; fixed 2.5.11ECOSYSTEM: introduced 2.6.0; fixed 2.6.6>=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.3.27|>=2.4.0,<2.5.0|>=2.5.0,<2.5.11|>=2.6.0,<2.6.6

Fixed versions: 2.3.27, 2.5.11, 2.6.6

Symfony Incorrect Access Control

Affected range

ECOSYSTEM: introduced 2.3.19; fixed 2.3.29ECOSYSTEM: introduced 2.5.4; fixed 2.5.12ECOSYSTEM: introduced 2.6.0; fixed 2.6.8ECOSYSTEM: introduced 2.4.9; last affected 2.4.10>=2.3.19,<2.3.29|>=2.4.9,<2.5.0|>=2.5.4,<2.5.12|>=2.6.0,<2.6.8

Fixed versions: 2.3.29, 2.5.12, 2.6.8