GHSA-w4rc-rx25-8m86 critical
Improper Input Validation in Symfony
Affected range
ECOSYSTEM: introduced 4.2.0; fixed 4.2.12ECOSYSTEM: introduced 4.3.0; fixed 4.3.8>=4.2.0,<4.2.12|>=4.3.0,<4.3.8Fixed versions: 4.2.12, 4.3.8
Provides tools to export, instantiate, hydrate, clone and lazy-load PHP objects
Evidence path
RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.
Latest version
8.1.6
No matching published advisory returned
Known exploitation
No KEV match
Checked by exact CVE identifier
Highest advisory severity
Critical
1 active advisory
The registry confirms the version, then OSV checks advisories for that exact value.
Published records
Affected range
ECOSYSTEM: introduced 4.2.0; fixed 4.2.12ECOSYSTEM: introduced 4.3.0; fixed 4.3.8>=4.2.0,<4.2.12|>=4.3.0,<4.3.8Fixed versions: 4.2.12, 4.3.8