Skip to content
RequestGuard Vulnerabilities
Pricing

symfony/serializer

Handles serializing and deserializing data structures, including object graphs, into array structures or other formats like XML and JSON.

Composer latest 8.1.7 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

8.1.7

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

2 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

2

Symfony XML decoding attack vector through external entities

Affected range

ECOSYSTEM: introduced 2.0.0; fixed 2.0.11>=2.0.0,<2.0.11

Fixed versions: 2.0.11

CSV Injection in symfony/serializer

Affected range

ECOSYSTEM: introduced 5.0.0; fixed 5.3.12ECOSYSTEM: introduced 4.1.0; fixed 4.4.35>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.35|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.3.12

Fixed versions: 5.3.12, 4.4.35