symfony
OSS Librariesoss-project
Latest CVEs
The 15 most recently published vulnerabilities affecting symfony.
- CVE-2026-49215Symfony UX: CSRF Protection Bypass in symfony/ux-live-component — Accept Header is CORS-Safelisted5.4
- CVE-2026-49216Symfony UX: XSS in symfony/ux-autocomplete via unescaped AJAX response data5.4
- CVE-2026-49211Symfony UX: Information exposure via unescaped LIKE wildcards in EntitySearchUtil7.5
- CVE-2026-49208Symfony UX: Format-less date LiveProps parsed with the permissive DateTime constructor5.3
- CVE-2026-49210Symfony UX: XSS in symfony/ux-live-component via attacker-controlled child component tag6.1
- CVE-2026-49212Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot binding7.5
- CVE-2026-49209Symfony UX: Denial of service in symfony/ux-live-component via unbounded batch action requests6.5
- CVE-2026-48807Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters9.1
- CVE-2026-48806Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys9.1
- CVE-2026-48808Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`7.5
- CVE-2026-48805Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`9.1
- CVE-2026-49981Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`8.2
- CVE-2026-46637Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`5.4
- CVE-2026-46638Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)8.1
- CVE-2026-46640Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation8.8