Symfony/symfony
This hub aggregates every CVE we track for Symfony/symfony, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
71
CVEs tracked
7
Critical
18
High
0
In CISA KEV
Severity distribution
MEDIUM29HIGH18CRITICAL7LOW4
Monthly trend
0
5
0
0
0
0
0
0
0
0
0
0
0
1
0
1
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Symfony/symfony.
- CVE-2026-24739Symfony has incorrect argument escaping under MSYS2/Git Bash on Windows that can lead to destructive file operations6.3
- CVE-2025-64500Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass7.3
- CVE-2024-50340Ability to change environment from query in symfony/runtime7.3
- CVE-2024-50341Security::login does not take into account custom user_checker in symfony/security-bundle3.1
- CVE-2024-50342Internal address and port enumeration allowed by NoPrivateNetworkHttpClient in symfony/http-client3.1
- CVE-2024-50343Incorrect response from Validator when input ends with `\n` in symfony/validator3.1
- CVE-2024-51736Command execution hijack on Windows with Process class in symfony/process
- CVE-2014-6072Symfony Cross-Site Request Forgery vulnerability in the Web Profiler
- GHSA-hx53-jchx-cr52Symfony2 improper IP based access control
- GHSA-q2gc-gg3x-7942Symfony XML Entity Expansion security vulnerability
- GHSA-mmcv-fvq8-r9x3Symfony XML decoding attack vector through external entities
- GHSA-7mx2-7q8p-pgmwSymfony may allow a user to switch to using another user's identity
- CVE-2014-5245Symfony allows direct access of ESI URLs behind a trusted proxy
- CVE-2015-2309Symfony has unsafe methods in the Request class
- CVE-2014-6061Symfony has a security issue when parsing the Authorization header
Product normalization is registry-driven with AI assist and human review. How it works