Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Symfony

Symfonyфреймворк c открытым исходным кодом, написанный на PHP.

Релизный цикл, информация об уязвимостях

Продукт: Symfony
Вендор: SensioLabs

График релизов

5.46.16.26.37.06.47.17.27.38.07.48.12021202220232024202520262027202820292030

Недавние уязвимости Symfony

Количество 378

debian логотип

CVE-2026-48784

16 дней назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-48784

16 дней назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-48761

16 дней назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-48761

16 дней назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on <object>, <applet>, <iframe>, and <img>, and <meta http-equiv="refresh"> URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-48760

16 дней назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-48760

16 дней назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstream consumers could decode or display. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-48747

16 дней назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-48747

16 дней назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed the request-selected algorithm to hash_hmac(), allowing a signature algorithm downgrade instead of enforcing Mailomat's documented SHA-256 webhook signature. This issue is fixed in versions 7.4.13 and 8.0.13.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-48736

16 дней назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2026-48736

16 дней назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2026-48784

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-48784

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.

CVSS3: 6.1
0%
Низкий
16 дней назад
debian логотип
CVE-2026-48761

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-48761

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on <object>, <applet>, <iframe>, and <img>, and <meta http-equiv="refresh"> URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.

CVSS3: 6.1
0%
Низкий
16 дней назад
debian логотип
CVE-2026-48760

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-48760

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstream consumers could decode or display. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.

CVSS3: 6.1
0%
Низкий
16 дней назад
debian логотип
CVE-2026-48747

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-48747

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed the request-selected algorithm to hash_hmac(), allowing a signature algorithm downgrade instead of enforcing Mailomat's documented SHA-256 webhook signature. This issue is fixed in versions 7.4.13 and 8.0.13.

CVSS3: 5.3
0%
Низкий
16 дней назад
debian логотип
CVE-2026-48736

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 8.6
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-48736

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.

CVSS3: 8.6
0%
Низкий
16 дней назад

Уязвимостей на страницу


Поделиться