Skip to content
RequestGuard Vulnerabilities
Pricing

symfony/runtime

Enables decoupling PHP applications from global state

Composer latest 8.0.14 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

8.0.14

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

High

3 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

3

Symfony allows changing the environment through a query

Affected range

ECOSYSTEM: introduced 5.3.0; fixed 5.4.46ECOSYSTEM: introduced 6.0.0; fixed 6.4.14ECOSYSTEM: introduced 7.0.0; fixed 7.1.7>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7

Fixed versions: 5.4.46, 6.4.14, 7.1.7

SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

Affected range

ECOSYSTEM: introduced 5.4.46; fixed 5.4.52ECOSYSTEM: introduced 6.4.14; fixed 6.4.40ECOSYSTEM: introduced 7.1.7; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=8.0.0,<8.0.12|>=7.1.7,<7.4.12|>=6.4.14,<6.4.40|>=5.4.46,<5.4.52

Fixed versions: 5.4.52, 6.4.40, 7.4.12, 8.0.12

CVE-2026-46626: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

Affected range

>=5.4.46,<5.4.52|>=6.4.14,<6.4.40|>=7.1.7,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12