Symfony
This hub aggregates every CVE we track for Symfony, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
67
CVEs tracked
7
Critical
21
High
0
In CISA KEV
Severity distribution
MEDIUM34HIGH21CRITICAL7LOW5
Monthly trend
0
0
0
0
7
0
0
0
0
0
0
0
0
0
0
0
1
1
1
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Symfony.
- CVE-2026-24739Symfony has incorrect argument escaping under MSYS2/Git Bash on Windows that can lead to destructive file operations6.3
- CVE-2025-68129Auth0-PHP SDK has Improper Audience Validation6.8
- CVE-2025-64500Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass7.3
- CVE-2024-36611In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request...7.5
- CVE-2024-51996Symphony has an Authentication Bypass via RememberMe7.5
- CVE-2024-50340Ability to change environment from query in symfony/runtime7.3
- CVE-2024-50341Security::login does not take into account custom user_checker in symfony/security-bundle3.1
- CVE-2024-50342Internal address and port enumeration allowed by NoPrivateNetworkHttpClient in symfony/http-client3.1
- CVE-2024-50343Incorrect response from Validator when input ends with `\n` in symfony/validator3.1
- CVE-2024-50345Open redirect via browser-sanitized URLs in symfony/http-foundation3.1
- CVE-2023-46735Symfony potential Cross-site Scripting in WebhookController6.1
- CVE-2023-46734Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters6.1
- CVE-2023-46733Symfony possible session fixation vulnerability6.5
- CVE-2022-24894Symfony storing cookie headers in HttpCache5.9
- CVE-2022-24895Symfony vulnerable to Session Fixation of CSRF tokens6.3
Product normalization is registry-driven with AI assist and human review. How it works