Skip to content
RequestGuard Vulnerabilities
Pricing

symfony/symfony

The Symfony PHP framework

Composer latest 8.1.7 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

8.1.7

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

104 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

104

Symfony Service IDs Allow Injection

Affected range

ECOSYSTEM: introduced 2.7.0; fixed 2.7.51ECOSYSTEM: introduced 2.8.0; fixed 2.8.50ECOSYSTEM: introduced 3.0.0; fixed 3.4.26ECOSYSTEM: introduced 4.0.0; fixed 4.1.12ECOSYSTEM: introduced 4.2.0; fixed 4.2.7

Fixed versions: 2.7.51, 2.8.50, 3.4.26, 4.1.12, 4.2.7

Symfony XML decoding attack vector through external entities

Affected range

ECOSYSTEM: introduced 2.0.0; fixed 2.0.11>=2.0.0,<2.0.19|>=2.1.0,<2.1.4

Fixed versions: 2.0.11

Symfony Authentication Bypass

Affected range

ECOSYSTEM: introduced 2.8.0; fixed 2.8.37ECOSYSTEM: introduced 3.0.0; fixed 3.3.17ECOSYSTEM: introduced 3.4.0; fixed 3.4.7ECOSYSTEM: introduced 4.0.0; fixed 4.0.7>=2.8.0,<2.8.37|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.7|>=4.0.0,<4.0.7

Fixed versions: 2.8.37, 3.3.17, 3.4.7, 4.0.7

Symfony Unsafe Cache Serialization Could Enable RCE

Affected range

ECOSYSTEM: introduced 3.1.0; fixed 3.4.35ECOSYSTEM: introduced 4.0.0; fixed 4.2.12ECOSYSTEM: introduced 4.3.0; fixed 4.3.8>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.35|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.2.12|>=4.3.0,<4.3.8

Fixed versions: 3.4.35, 4.2.12, 4.3.8

Symfony Authentication Bypass

Affected range

ECOSYSTEM: introduced 2.8.0; fixed 2.8.6ECOSYSTEM: introduced 3.0.0; fixed 3.0.6>=2.8.0,<2.8.6|>=3.0.0,<3.0.6

Fixed versions: 2.8.6, 3.0.6

Symfony Incorrect Access Control

Affected range

ECOSYSTEM: introduced 2.7.30; fixed 2.7.32ECOSYSTEM: introduced 2.8.23; fixed 2.8.25ECOSYSTEM: introduced 3.2.10; fixed 3.2.12ECOSYSTEM: introduced 3.3.3; fixed 3.3.5>=2.7.30,<2.7.32|>=2.8.23,<2.8.25|>=3.2.10,<3.2.12|>=3.3.3,<3.3.5

Fixed versions: 2.7.32, 2.8.25, 3.2.12, 3.3.5

Improper Input Validation in Symfony

Affected range

ECOSYSTEM: introduced 4.2.0; fixed 4.2.12ECOSYSTEM: introduced 4.3.0; fixed 4.3.8>=4.2.0,<4.2.12|>=4.3.0,<4.3.8

Fixed versions: 4.2.12, 4.3.8

Invalid HTTP method overrides allow possible XSS or other attacks in Symfony

Affected range

ECOSYSTEM: introduced 2.7.0; fixed 2.7.51ECOSYSTEM: introduced 2.8.0; fixed 2.8.50ECOSYSTEM: introduced 3.0.0; fixed 3.4.26ECOSYSTEM: introduced 4.0.0; fixed 4.1.12ECOSYSTEM: introduced 4.2.0; fixed 4.2.7

Fixed versions: 2.7.51, 2.8.50, 3.4.26, 4.1.12, 4.2.7

Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes

Affected range

ECOSYSTEM: introduced 0; fixed 5.4.53ECOSYSTEM: introduced 6.0.0; fixed 6.4.41ECOSYSTEM: introduced 7.0.0; fixed 7.4.13ECOSYSTEM: introduced 8.0.0; fixed 8.0.13>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.53|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.41|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.13|>=8.0.0,<8.0.13

Fixed versions: 5.4.53, 6.4.41, 7.4.13, 8.0.13

Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator

Affected range

ECOSYSTEM: introduced 0; fixed 5.4.52ECOSYSTEM: introduced 6.0.0-BETA1; fixed 6.4.40ECOSYSTEM: introduced 7.0.0-BETA1; fixed 7.4.12ECOSYSTEM: introduced 8.0.0-BETA1; fixed 8.0.12>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12

Fixed versions: 5.4.52, 6.4.40, 7.4.12, 8.0.12

Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener

Affected range

ECOSYSTEM: introduced 0; fixed 5.4.52ECOSYSTEM: introduced 6.0.0; fixed 6.4.40ECOSYSTEM: introduced 7.0.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12

Fixed versions: 5.4.52, 6.4.40, 7.4.12, 8.0.12

Symfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]

Affected range

ECOSYSTEM: introduced 7.4.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=7.4.0,<7.4.12|>=8.0.0,<8.0.12

Fixed versions: 7.4.12, 8.0.12

Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address

Affected range

ECOSYSTEM: introduced 0; fixed 5.4.52ECOSYSTEM: introduced 6.0.0; fixed 6.4.40ECOSYSTEM: introduced 7.0.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12

Fixed versions: 5.4.52, 6.4.40, 7.4.12, 8.0.12

Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass

Affected range

ECOSYSTEM: introduced 2.0.0; fixed 5.4.50ECOSYSTEM: introduced 6.0.0; fixed 6.4.29ECOSYSTEM: introduced 7.0.0; fixed 7.3.7>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.50|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.29|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.3.7

Fixed versions: 5.4.50, 6.4.29, 7.3.7

Symfony vulnerable to command execution hijack on Windows with Process class

Affected range

ECOSYSTEM: introduced 0; fixed 5.4.46ECOSYSTEM: introduced 6.0.0; fixed 6.4.14ECOSYSTEM: introduced 7.0.0; fixed 7.1.7>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7

Fixed versions: 5.4.46, 6.4.14, 7.1.7

Firewall configured with unanimous strategy was not actually unanimous in Symfony

Affected range

ECOSYSTEM: introduced 4.4.0; fixed 4.4.7ECOSYSTEM: introduced 5.0.0; fixed 5.0.7>=4.4.0,<4.4.7|>=5.0.0,<5.0.7

Fixed versions: 4.4.7, 5.0.7

RCE in Symfony

Affected range

ECOSYSTEM: introduced 4.3.0; fixed 4.4.13ECOSYSTEM: introduced 5.0.0; fixed 5.1.5>=4.3.0,<4.4.0|>=4.4.0,<4.4.13|>=5.0.0,<5.1.0|>=5.1.0,<5.1.5

Fixed versions: 4.4.13, 5.1.5

Symfony Arbitrary PHP code Execution

Affected range

ECOSYSTEM: introduced 2.2.0-BETA1; fixed 2.2.0-BETA2ECOSYSTEM: introduced 2.0.0; fixed 2.0.22ECOSYSTEM: introduced 2.1.0; fixed 2.1.7>=2.0.0,<2.0.22|>=2.1.0,<2.1.7

Fixed versions: 2.2.0-BETA2, 2.0.22, 2.1.7

Symphony Denial of Service Via Overlong Usernames

Affected range

ECOSYSTEM: introduced 2.3.0; fixed 2.3.41ECOSYSTEM: introduced 2.4.0; fixed 2.7.13ECOSYSTEM: introduced 2.8.0; fixed 2.8.6ECOSYSTEM: introduced 3.0.0; fixed 3.0.6>=2.3.0,<2.3.41|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.13|>=2.8.0,<2.8.6|>=3.0.0,<3.0.6

Fixed versions: 2.3.41, 2.7.13, 2.8.6, 3.0.6

Symfony XML Entity Expansion security vulnerability

Affected range

ECOSYSTEM: introduced 2.0.0; fixed 2.0.17>=2.0.0,<2.0.17

Fixed versions: 2.0.17

Symfony Vulnerable to Timing Attack

Affected range

ECOSYSTEM: introduced 2.3.0; fixed 2.3.35ECOSYSTEM: introduced 2.7.0; fixed 2.7.7ECOSYSTEM: introduced 2.4.0; fixed 2.6.12>=2.3.0,<2.3.35|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7

Fixed versions: 2.3.35, 2.7.7, 2.6.12

Symfony allows changing the environment through a query

Affected range

ECOSYSTEM: introduced 5.3.0; fixed 5.4.46ECOSYSTEM: introduced 6.0.0; fixed 6.4.14ECOSYSTEM: introduced 7.0.0; fixed 7.1.7>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7

Fixed versions: 5.4.46, 6.4.14, 7.1.7

Symfony Cross-Site Request Forgery vulnerability in the Web Profiler

Affected range

ECOSYSTEM: introduced 2.0.0; fixed 2.3.19ECOSYSTEM: introduced 2.4.0; fixed 2.4.9ECOSYSTEM: introduced 2.5.0; fixed 2.5.4>=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.3.19|>=2.4.0,<2.4.9|>=2.5.0,<2.5.4

Fixed versions: 2.3.19, 2.4.9, 2.5.4

Symfony allows direct access of ESI URLs behind a trusted proxy

Affected range

ECOSYSTEM: introduced 2.0.0; fixed 2.3.19ECOSYSTEM: introduced 2.4.0; fixed 2.4.9ECOSYSTEM: introduced 2.5.0; fixed 2.5.4>=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.3.19|>=2.4.0,<2.4.9|>=2.5.0,<2.5.4

Fixed versions: 2.3.19, 2.4.9, 2.5.4

Show 75 more advisories
GHSA-v77v-x634-9m56 Symfony vulnerable to denial of service via a malicious HTTP Host header
GHSA-wfv7-5x33-v22h Code injection in the way Symfony implements translation caching in FrameworkBundle
GHSA-w2fr-65vp-mxw3 Deserialization of untrusted data in Symfony
GHSA-xhh6-956q-4q69 Argument injection in a MimeTypeGuesser in Symfony
GHSA-q8hg-pf8v-cxrv Symfony Http-Kernel has non-constant time comparison in UriSigner
GHSA-jjx5-fq5g-8xpc Symfony Cryptographic Vulnerability
GHSA-g4g7-q726-v5hg Symfony CSRF Token Fixation
GHSA-g4rg-rw65-8hfg Symfony Session Fixation Vulnerability
GHSA-c49r-8gj6-768r Symfony Directory Traversal
GHSA-66p6-7p29-55p9 Symfony Host Header Injection
GHSA-q8j7-fjh7-25v5 Symfony collectionCascaded and collectionCascadedDeeply fields security bypass
GHSA-cchx-mfrc-fwqr Improper authentication in Symfony
PKSA-hs3m-xyq3-pnj7 CVE-2022-23601: CSRF token missing in forms
GHSA-v3wm-qf9p-c549 Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
GHSA-38cx-cq6f-5755 Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
GHSA-xx3c-qf5g-hc39 Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address
GHSA-vqc8-7275-q272 Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names
GHSA-h5vq-qfcg-4m6p Symfony's HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
GHSA-55rj-x2vc-4whq Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification
GHSA-r39x-jcww-82v6 Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows
GHSA-x5qj-865h-mgvm Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes
GHSA-rrj9-5q2j-4gvr Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
GHSA-h5x3-xfc9-m39h Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
GHSA-fqc7-9xjw-jrh3 SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
GHSA-qc95-4862-92fh Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification
GHSA-j8gj-9rm5-4xhx Symfony's Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
GHSA-6qh9-h6wf-jgqc Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix
GHSA-72xp-p242-47p9 Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
GHSA-64hg-93w9-fc35 Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
GHSA-59f3-vp2f-mp9w Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection
GHSA-29fc-p6c4-24cg Symfony's OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims
GHSA-m2wj-r6g3-fxfx Symfony possible session fixation vulnerability
GHSA-q847-2q57-wmr3 Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters
GHSA-72x2-5c85-6wmr Symfony potential Cross-site Scripting in WebhookController
GHSA-5pv8-ppvj-4h68 Prevent user enumeration using Guard or the new Authenticator-based Security
GHSA-m884-279h-32v2 Exceptions displayed in non-debug configurations in Symfony
GHSA-qw36-p97w-vcqr Cookie persistence after password changes in symfony/security-bundle
GHSA-2xhg-w2g5-w95x CSV Injection in symfony/serializer
GHSA-q3j3-w37x-hq2q Webcache Poisoning in symfony/http-kernel
GHSA-rfcf-m67m-jcrq Authentication granted to all firewalls instead of just one
GHSA-h7vf-5wrv-9fhv Symfony storing cookie headers in HttpCache
GHSA-3gv2-29qc-v67m Symfony vulnerable to Session Fixation of CSRF tokens
GHSA-cr49-fx2v-9p57 Symfony Denial of Service Via Long Password Hashing
GHSA-5c58-w9xc-qcj9 Symfony Vulnerable to PHP Eval Injection
GHSA-qmqw-mpqp-mr54 Symfony Incorrect Access Control
GHSA-hx53-jchx-cr52 Symfony2 improper IP based access control
GHSA-vfm6-r2gc-pwww Symfony2 security issue when the trust proxy mode is enabled
GHSA-7mx2-7q8p-pgmw Symfony may allow a user to switch to using another user's identity
GHSA-83c3-qx27-2rwr Symfony Allows URI Restrictions Bypass Via Double-Encoded String
GHSA-89cp-fvcc-hxh7 Symfony Access Control Vulnerability
GHSA-p684-f7fh-jv2j Symfony has unsafe methods in the Request class
GHSA-h7v2-2qwg-h829 Symfony has a security issue when parsing the Authorization header
GHSA-89r2-5g34-2g47 Symfony Open Redirect
GHSA-cqqh-94r6-wjrg Symfony SSRF Vulnerability via Form Component
GHSA-22pv-7v9j-hqxp Symfony Host Header Injection vulnerability in the HttpFoundation component
GHSA-7hwc-2cq4-6x2w Symfony Open Redirect
GHSA-r2rq-3h56-fqm4 Symfony DoS
GHSA-g996-q5r8-w7g2 Symfony Cross-site Scripting (XSS) vulnerability
GHSA-r7p7-qr7p-2rrf Symfony Open Redirect
GHSA-92x6-h2gr-8gxq Symfony CSRF Vulnerability
GHSA-8wgj-6wx8-h5hq Symfony HTTP Foundation web cache poisoning
GHSA-x3cf-w64x-4cp2 Symfony Path Disclosure
GHSA-4vpc-5jx4-cfqg User enumeration leak using switch user functionality in Symfony
GHSA-hhg7-c65m-h7ff Symfony's HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — `javascript`: URI Survives Sanitization (XSS)
GHSA-hmr5-2xcr-v8pp Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
GHSA-9frc-8383-795m Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
GHSA-x6g4-fwcc-jj8w Symfony has XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
GHSA-c2p3-7m5p-cv8x Symfony hardened the parser when handling untrusted input
GHSA-8v8v-g73j-492j Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
GHSA-4qpc-3hr4-r2p4 Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
GHSA-mcx4-f5f5-4859 Prevent cache poisoning via a Response Content-Type header in Symfony
GHSA-9c3x-r3wp-mgxm Symfony allows internal address and port enumeration by NoPrivateNetworkHttpClient
GHSA-g3rh-rrhp-jhh9 Symfony has an incorrect response from Validator when input ends with `\n`
GHSA-g2qj-pmxm-9f8f User enumeration in authentication mechanisms
GHSA-jxgr-3v7q-3w9v Symfony's `Security::login` does not take into account custom `user_checker`