CVE-2026-45073: Symfony: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix

Published May 27, 2026
·
Updated

Description

Symfony\Component\Cache\Adapter\PdoAdapter is the PDO-backed cache adapter. Its clear($prefix) method (inherited from AbstractAdapterTrait) is documented to delete cache items whose key starts with $prefix.

In the non-versioning code path, the caller-supplied $prefix is concatenated into $namespace = $this->namespace.$prefix and passed to PdoAdapter::doClear(), which builds:

sql DELETE FROM <table> WHERE <idcol> LIKE '<namespace>%'

The value is interpolated directly into the SQL text and executed with PDO::exec(): $namespace is not bound. A caller able to influence $prefix can break out of the literal and inject SQL, expanding deletion scope from the intended prefix to arbitrary rows, or otherwise reshape query semantics.

Most applications don't expose clear($prefix) to untrusted input directly, but the contract of the method is to safely accept any prefix string, so the lack of escaping is a defect of the adapter itself.

Resolution

AbstractAdapterTrait::clear() now rejects any $prefix containing characters outside [-+.A-Za-z0-9]: when an invalid prefix is supplied, the method logs a warning and returns false instead of reaching the SQL layer. This blocks quotes, %, null bytes and other characters that would let an attacker break out of the LIKE literal.

The patch for this issue is available here for branch 5.4.

Credits Symfony would like to thank secsyscodex for reporting the issue and Nicolas Grekas for fixing it.

Other sources

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence $prefix to break out of the LIKE literal and alter query semantics or deletion scope. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

MITRE

Affected Software

12 affected componentsFixes available
composer/symfony/symfony>=8.0.0<8.0.12
8.0.12
composer/symfony/symfony>=7.0.0<7.4.12
7.4.12
composer/symfony/symfony>=6.0.0<6.4.40
6.4.40
composer/symfony/symfony<5.4.52
5.4.52
composer/symfony/cache>=8.0.0<8.0.12
8.0.12
composer/symfony/cache>=7.0.0<7.4.12
7.4.12
composer/symfony/cache>=6.0.0<6.4.40
6.4.40
composer/symfony/cache<5.4.52
5.4.52
SensioLabs Symfony<5.4.52
SensioLabs Symfony>=6.0.0<6.4.40
SensioLabs Symfony>=7.0.0<7.4.12
SensioLabs Symfony>=8.0.0<8.0.12

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/symfony/symfony to a version that resolves this vulnerability.

    Fixed in 8.0.12
  2. Upgrade

    Upgrade composer/symfony/symfony to a version that resolves this vulnerability.

    Fixed in 7.4.12
  3. Upgrade

    Upgrade composer/symfony/symfony to a version that resolves this vulnerability.

    Fixed in 6.4.40
  4. Upgrade

    Upgrade composer/symfony/symfony to a version that resolves this vulnerability.

    Fixed in 5.4.52
  5. Upgrade

    Upgrade composer/symfony/cache to a version that resolves this vulnerability.

    Fixed in 8.0.12
  6. Upgrade

    Upgrade composer/symfony/cache to a version that resolves this vulnerability.

    Fixed in 7.4.12
  7. Upgrade

    Upgrade composer/symfony/cache to a version that resolves this vulnerability.

    Fixed in 6.4.40
  8. Upgrade

    Upgrade composer/symfony/cache to a version that resolves this vulnerability.

    Fixed in 5.4.52
  9. Upgrade

    Upgrade Symfony (Symfony Cache PdoAdapter via AbstractAdapterTrait::clear) to a version that resolves this vulnerability.

    Fixed in 5.4.52
  10. Upgrade

    Upgrade Symfony (Symfony Cache PdoAdapter via AbstractAdapterTrait::clear) to a version that resolves this vulnerability.

    Fixed in 6.4.40
  11. Upgrade

    Upgrade Symfony (Symfony Cache PdoAdapter via AbstractAdapterTrait::clear) to a version that resolves this vulnerability.

    Fixed in 7.4.12
  12. Upgrade

    Upgrade Symfony (Symfony Cache PdoAdapter via AbstractAdapterTrait::clear) to a version that resolves this vulnerability.

    Fixed in 8.0.12
  13. Configuration

    Ensure AbstractAdapterTrait::clear() rejects any $prefix containing characters outside `[-+.A-Za-z0-9]`, logs a warning, and returns false instead of executing the SQL DELETE in PdoAdapter::doClear().

    Symfony\Component\Cache\Adapter\PdoAdapter (AbstractAdapterTrait::clear) $prefix validation (reject characters outside `[-+.A-Za-z0-9]`) = enabled/reject invalid prefixes

Event History

May 27, 2026
Advisory Published
via GitHub·09:11 PM
Data Sourced
via GitHub·09:11 PM
DescriptionWeaknessAffected Software
Jul 14, 2026
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-45073?

CVE-2026-45073 has a risk rating of 37, indicating a significant vulnerability.

2

What type of vulnerability is CVE-2026-45073?

CVE-2026-45073 is classified as an SQL Injection vulnerability.

3

How do I fix CVE-2026-45073?

To fix CVE-2026-45073, update to the latest version of Symfony that addresses this vulnerability.

4

What components are affected by CVE-2026-45073?

CVE-2026-45073 affects the Symfony component, specifically the PDO-backed cache adapter.

5

What is the impact of CVE-2026-45073?

The impact of CVE-2026-45073 allows attackers to potentially manipulate SQL queries through improperly handled user input.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203