Search CVE reports


Toggle filters

21 – 30 of 91 results


CVE-2026-45070

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45069

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp)...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45064

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45063

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45756

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45077

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45074

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45067

Medium priority
Needs evaluation

### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input,...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45066

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization can allow off-allowlist URLs...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45065

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages