GHSA-j68w-pg49-f6vx critical
Symfony XML decoding attack vector through external entities
Affected range
ECOSYSTEM: introduced 2.0.0; fixed 2.0.11>=2.0.0,<2.0.11Fixed versions: 2.0.11
Handles serializing and deserializing data structures, including object graphs, into array structures or other formats like XML and JSON.
Evidence path
RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.
Latest version
8.1.7
No matching published advisory returned
Known exploitation
No KEV match
Checked by exact CVE identifier
Highest advisory severity
Critical
2 active advisories
The registry confirms the version, then OSV checks advisories for that exact value.
Published records
Affected range
ECOSYSTEM: introduced 2.0.0; fixed 2.0.11>=2.0.0,<2.0.11Fixed versions: 2.0.11
Affected range
ECOSYSTEM: introduced 5.0.0; fixed 5.3.12ECOSYSTEM: introduced 4.1.0; fixed 4.4.35>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.35|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.3.12Fixed versions: 5.3.12, 4.4.35