Where
-Infinity
0

composer/symfony/symfonySymfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization

Risk 38
Severity
5.1
First published (updated )

composer/symfony/symfonySymfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Risk 38
Severity
5.3
First published (updated )

composer/symfony/symfonySymfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

Risk 29
Severity
6.3
First published (updated )

composer/symfony/symfonySymfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

Risk 49
Severity
6.9
First published (updated )

composer/symfony/symfonySymfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/symfony/symfonySymfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> content

Risk 38
Severity
5.3
First published (updated )

composer/symfony/symfonySymfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

Risk 86
Severity
8.3
First published (updated )

composer/symfony/twilio-notifierSymfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event Injection

Risk 33
Severity
6.9
First published (updated )

composer/symfony/symfonySymfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS

Risk 43
Severity
8.2
First published (updated )

composer/symfony/symfonySymfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection

Risk 33
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/symfony/mailjet-mailerSymfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection

Risk 33
Severity
6.9
First published (updated )

composer/symfony/symfonySymfony: HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — javascript: URI Survives Sanitization (XSS)

Risk 38
Severity
2.1
First published (updated )

composer/symfony/yamlSymfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex

Risk 47
Severity
8.7
First published (updated )

composer/symfony/yamlSymfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")

Risk 47
Severity
8.7
First published (updated )

composer/symfony/yamlSymfony: [Yaml] Harden the parser when handling untrusted input

Risk 43
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/symfony/symfonySymfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener

Risk 64
Severity
8.3
First published (updated )

composer/symfony/symfonySymfony: HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]

Risk 52
Severity
8.3
First published (updated )

composer/symfony/symfonySymfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay

Risk 59
Severity
7.6
First published (updated )

composer/symfony/symfonySymfony: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix

Risk 51
Severity
6.3
First published (updated )

composer/symfony/symfonySymfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering

Risk 34
Severity
2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/symfony/symfonySymfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true

Risk 47
Severity
8.7
First published (updated )

composer/symfony/symfonySymfony: Email Header Injection via Non-Token Characters in Mime Parameter Names

Risk 40
Severity
6.3
First published (updated )

composer/symfony/symfonySymfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims

Risk 66
Severity
8.8
First published (updated )

composer/symfony/symfonySymfony: Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address

Risk 47
Severity
8.7
First published (updated )

composer/symfony/symfonySymfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification

Risk 38
Severity
2.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/symfony/symfonySymfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing

Risk 38
Severity
2.3
First published (updated )

composer/symfony/symfonySymfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection

Risk 38
Severity
2.3
First published (updated )

composer/symfony/symfonySymfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator

Risk 63
Severity
9.1
First published (updated )

composer/symfony/symfonySymfony has incorrect argument escaping under MSYS2/Git Bash on Windows that can lead to destructive file operations

Risk 35
Severity
6.3
EPSS
0.01%
First published (updated )

composer/symfony/symfonySymfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass

Risk 51
Severity
7.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203