Symfony Service IDs Allow Injection May 29, 2025 Affected range
ECOSYSTEM: introduced 2.7.0; fixed 2.7.51ECOSYSTEM: introduced 2.8.0; fixed 2.8.50ECOSYSTEM: introduced 3.0.0; fixed 3.4.26ECOSYSTEM: introduced 4.0.0; fixed 4.1.12ECOSYSTEM: introduced 4.2.0; fixed 4.2.7
Fixed versions: 2.7.51, 2.8.50, 3.4.26, 4.1.12, 4.2.7
Symfony XML decoding attack vector through external entities Dec 5, 2024 Affected range
ECOSYSTEM: introduced 2.0.0; fixed 2.0.11>=2.0.0,<2.0.19|>=2.1.0,<2.1.4
Fixed versions: 2.0.11
Symfony Authentication Bypass Apr 25, 2024 Affected range
ECOSYSTEM: introduced 2.8.0; fixed 2.8.37ECOSYSTEM: introduced 3.0.0; fixed 3.3.17ECOSYSTEM: introduced 3.4.0; fixed 3.4.7ECOSYSTEM: introduced 4.0.0; fixed 4.0.7>=2.8.0,<2.8.37|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.7|>=4.0.0,<4.0.7
Fixed versions: 2.8.37, 3.3.17, 3.4.7, 4.0.7
Symfony Unsafe Cache Serialization Could Enable RCE Feb 20, 2024 Affected range
ECOSYSTEM: introduced 3.1.0; fixed 3.4.35ECOSYSTEM: introduced 4.0.0; fixed 4.2.12ECOSYSTEM: introduced 4.3.0; fixed 4.3.8>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.35|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.2.12|>=4.3.0,<4.3.8
Fixed versions: 3.4.35, 4.2.12, 4.3.8
Symfony Authentication Bypass Feb 16, 2024 Affected range
ECOSYSTEM: introduced 2.8.0; fixed 2.8.6ECOSYSTEM: introduced 3.0.0; fixed 3.0.6>=2.8.0,<2.8.6|>=3.0.0,<3.0.6
Fixed versions: 2.8.6, 3.0.6
Symfony Incorrect Access Control Feb 16, 2024 Affected range
ECOSYSTEM: introduced 2.7.30; fixed 2.7.32ECOSYSTEM: introduced 2.8.23; fixed 2.8.25ECOSYSTEM: introduced 3.2.10; fixed 3.2.12ECOSYSTEM: introduced 3.3.3; fixed 3.3.5>=2.7.30,<2.7.32|>=2.8.23,<2.8.25|>=3.2.10,<3.2.12|>=3.3.3,<3.3.5
Fixed versions: 2.7.32, 2.8.25, 3.2.12, 3.3.5
Improper Input Validation in Symfony Nov 8, 2023 Affected range
ECOSYSTEM: introduced 4.2.0; fixed 4.2.12ECOSYSTEM: introduced 4.3.0; fixed 4.3.8>=4.2.0,<4.2.12|>=4.3.0,<4.3.8
Fixed versions: 4.2.12, 4.3.8
Invalid HTTP method overrides allow possible XSS or other attacks in Symfony Nov 8, 2023 Affected range
ECOSYSTEM: introduced 2.7.0; fixed 2.7.51ECOSYSTEM: introduced 2.8.0; fixed 2.8.50ECOSYSTEM: introduced 3.0.0; fixed 3.4.26ECOSYSTEM: introduced 4.0.0; fixed 4.1.12ECOSYSTEM: introduced 4.2.0; fixed 4.2.7
Fixed versions: 2.7.51, 2.8.50, 3.4.26, 4.1.12, 4.2.7
Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes Sep 10, 2026 Affected range
ECOSYSTEM: introduced 0; fixed 5.4.53ECOSYSTEM: introduced 6.0.0; fixed 6.4.41ECOSYSTEM: introduced 7.0.0; fixed 7.4.13ECOSYSTEM: introduced 8.0.0; fixed 8.0.13>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.53|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.41|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.13|>=8.0.0,<8.0.13
Fixed versions: 5.4.53, 6.4.41, 7.4.13, 8.0.13
Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator Sep 10, 2026 Affected range
ECOSYSTEM: introduced 0; fixed 5.4.52ECOSYSTEM: introduced 6.0.0-BETA1; fixed 6.4.40ECOSYSTEM: introduced 7.0.0-BETA1; fixed 7.4.12ECOSYSTEM: introduced 8.0.0-BETA1; fixed 8.0.12>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
Fixed versions: 5.4.52, 6.4.40, 7.4.12, 8.0.12
Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener Sep 10, 2026 Affected range
ECOSYSTEM: introduced 0; fixed 5.4.52ECOSYSTEM: introduced 6.0.0; fixed 6.4.40ECOSYSTEM: introduced 7.0.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
Fixed versions: 5.4.52, 6.4.40, 7.4.12, 8.0.12
Symfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid] Sep 10, 2026 Affected range
ECOSYSTEM: introduced 7.4.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
Fixed versions: 7.4.12, 8.0.12
Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address Sep 10, 2026 Affected range
ECOSYSTEM: introduced 0; fixed 5.4.52ECOSYSTEM: introduced 6.0.0; fixed 6.4.40ECOSYSTEM: introduced 7.0.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
Fixed versions: 5.4.52, 6.4.40, 7.4.12, 8.0.12
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass Sep 10, 2026 Affected range
ECOSYSTEM: introduced 2.0.0; fixed 5.4.50ECOSYSTEM: introduced 6.0.0; fixed 6.4.29ECOSYSTEM: introduced 7.0.0; fixed 7.3.7>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.50|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.29|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.3.7
Fixed versions: 5.4.50, 6.4.29, 7.3.7
Symfony vulnerable to command execution hijack on Windows with Process class Sep 10, 2026 Affected range
ECOSYSTEM: introduced 0; fixed 5.4.46ECOSYSTEM: introduced 6.0.0; fixed 6.4.14ECOSYSTEM: introduced 7.0.0; fixed 7.1.7>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7
Fixed versions: 5.4.46, 6.4.14, 7.1.7
Firewall configured with unanimous strategy was not actually unanimous in Symfony Sep 10, 2026 Affected range
ECOSYSTEM: introduced 4.4.0; fixed 4.4.7ECOSYSTEM: introduced 5.0.0; fixed 5.0.7>=4.4.0,<4.4.7|>=5.0.0,<5.0.7
Fixed versions: 4.4.7, 5.0.7
Affected range
ECOSYSTEM: introduced 4.3.0; fixed 4.4.13ECOSYSTEM: introduced 5.0.0; fixed 5.1.5>=4.3.0,<4.4.0|>=4.4.0,<4.4.13|>=5.0.0,<5.1.0|>=5.1.0,<5.1.5
Fixed versions: 4.4.13, 5.1.5
Symfony Arbitrary PHP code Execution Apr 14, 2025 Affected range
ECOSYSTEM: introduced 2.2.0-BETA1; fixed 2.2.0-BETA2ECOSYSTEM: introduced 2.0.0; fixed 2.0.22ECOSYSTEM: introduced 2.1.0; fixed 2.1.7>=2.0.0,<2.0.22|>=2.1.0,<2.1.7
Fixed versions: 2.2.0-BETA2, 2.0.22, 2.1.7
Symphony Denial of Service Via Overlong Usernames Dec 8, 2024 Affected range
ECOSYSTEM: introduced 2.3.0; fixed 2.3.41ECOSYSTEM: introduced 2.4.0; fixed 2.7.13ECOSYSTEM: introduced 2.8.0; fixed 2.8.6ECOSYSTEM: introduced 3.0.0; fixed 3.0.6>=2.3.0,<2.3.41|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.13|>=2.8.0,<2.8.6|>=3.0.0,<3.0.6
Fixed versions: 2.3.41, 2.7.13, 2.8.6, 3.0.6
Symphony Vulnerable to PHP Code Injection via YAML Parsing Dec 8, 2024 Affected range
ECOSYSTEM: introduced 2.0.0; fixed 2.0.22>=2.0.0,<2.0.22
Fixed versions: 2.0.22
Symfony XML Entity Expansion security vulnerability Dec 5, 2024 Affected range
ECOSYSTEM: introduced 2.0.0; fixed 2.0.17>=2.0.0,<2.0.17
Fixed versions: 2.0.17
Symfony Vulnerable to Timing Attack Nov 30, 2024 Affected range
ECOSYSTEM: introduced 2.3.0; fixed 2.3.35ECOSYSTEM: introduced 2.7.0; fixed 2.7.7ECOSYSTEM: introduced 2.4.0; fixed 2.6.12>=2.3.0,<2.3.35|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7
Fixed versions: 2.3.35, 2.7.7, 2.6.12
Symfony allows changing the environment through a query Nov 7, 2024 Affected range
ECOSYSTEM: introduced 5.3.0; fixed 5.4.46ECOSYSTEM: introduced 6.0.0; fixed 6.4.14ECOSYSTEM: introduced 7.0.0; fixed 7.1.7>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7
Fixed versions: 5.4.46, 6.4.14, 7.1.7
Symfony Cross-Site Request Forgery vulnerability in the Web Profiler May 30, 2024 Affected range
ECOSYSTEM: introduced 2.0.0; fixed 2.3.19ECOSYSTEM: introduced 2.4.0; fixed 2.4.9ECOSYSTEM: introduced 2.5.0; fixed 2.5.4>=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.3.19|>=2.4.0,<2.4.9|>=2.5.0,<2.5.4
Fixed versions: 2.3.19, 2.4.9, 2.5.4
Symfony allows direct access of ESI URLs behind a trusted proxy May 30, 2024 Affected range
ECOSYSTEM: introduced 2.0.0; fixed 2.3.19ECOSYSTEM: introduced 2.4.0; fixed 2.4.9ECOSYSTEM: introduced 2.5.0; fixed 2.5.4>=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.3.19|>=2.4.0,<2.4.9|>=2.5.0,<2.5.4
Fixed versions: 2.3.19, 2.4.9, 2.5.4
Show 75 more advisories GHSA-wfv7-5x33-v22h Code injection in the way Symfony implements translation caching in FrameworkBundle GHSA-q8j7-fjh7-25v5 Symfony collectionCascaded and collectionCascadedDeeply fields security bypass GHSA-v3wm-qf9p-c549 Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense GHSA-38cx-cq6f-5755 Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient GHSA-xx3c-qf5g-hc39 Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address GHSA-vqc8-7275-q272 Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names GHSA-h5vq-qfcg-4m6p Symfony's HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing GHSA-55rj-x2vc-4whq Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification GHSA-r39x-jcww-82v6 Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows GHSA-rrj9-5q2j-4gvr Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade GHSA-h5x3-xfc9-m39h Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization GHSA-fqc7-9xjw-jrh3 SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch GHSA-qc95-4862-92fh Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification GHSA-j8gj-9rm5-4xhx Symfony's Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay GHSA-6qh9-h6wf-jgqc Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix GHSA-72xp-p242-47p9 Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection GHSA-64hg-93w9-fc35 Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection GHSA-59f3-vp2f-mp9w Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection GHSA-q847-2q57-wmr3 Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters GHSA-5pv8-ppvj-4h68 Prevent user enumeration using Guard or the new Authenticator-based Security GHSA-22pv-7v9j-hqxp Symfony Host Header Injection vulnerability in the HttpFoundation component GHSA-hhg7-c65m-h7ff Symfony's HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — `javascript`: URI Survives Sanitization (XSS) GHSA-hmr5-2xcr-v8pp Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering GHSA-9frc-8383-795m Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex GHSA-x6g4-fwcc-jj8w Symfony has XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true GHSA-8v8v-g73j-492j Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS GHSA-4qpc-3hr4-r2p4 Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs") GHSA-9c3x-r3wp-mgxm Symfony allows internal address and port enumeration by NoPrivateNetworkHttpClient GHSA-jxgr-3v7q-3w9v Symfony's `Security::login` does not take into account custom `user_checker`