Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Symfony

Symfonyфреймворк c открытым исходным кодом, написанный на PHP.

Релизный цикл, информация об уязвимостях

Продукт: Symfony
Вендор: SensioLabs

График релизов

5.46.16.26.37.06.47.17.27.38.07.48.12021202220232024202520262027202820292030

Недавние уязвимости Symfony

Количество 378

nvd логотип

CVE-2026-45133

16 дней назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parsers to recurse without a depth limit. A crafted document exhausts the PHP stack and crashes the worker. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-45075

16 дней назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-45075

16 дней назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check is skipped, allowing protected controllers to execute and leak headers or perform side effects. This issue is fixed in versions 7.4.12 and 8.0.12.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2026-45073

16 дней назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-45073

16 дней назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence $prefix to break out of the LIKE literal and alter query semantics or deletion scope. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2026-45072

16 дней назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-45072

16 дней назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the development profiler file_excerpt Twig filter escapes PHP files through highlight_string() but interpolates lines from non-PHP files directly into <code> elements, allowing stored XSS against a developer who opens an attacker-written file such as var/log/dev.log in the profiler. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2026-45070

16 дней назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-45070

16 дней назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-45069

16 дней назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2026-45133

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parsers to recurse without a depth limit. A crafted document exhausts the PHP stack and crashes the worker. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

CVSS3: 7.5
1%
Низкий
16 дней назад
debian логотип
CVE-2026-45075

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 8.2
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-45075

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check is skipped, allowing protected controllers to execute and leak headers or perform side effects. This issue is fixed in versions 7.4.12 and 8.0.12.

CVSS3: 8.2
0%
Низкий
16 дней назад
debian логотип
CVE-2026-45073

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 7.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-45073

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence $prefix to break out of the LIKE literal and alter query semantics or deletion scope. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

CVSS3: 7.3
0%
Низкий
16 дней назад
debian логотип
CVE-2026-45072

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 5.4
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-45072

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the development profiler file_excerpt Twig filter escapes PHP files through highlight_string() but interpolates lines from non-PHP files directly into <code> elements, allowing stored XSS against a developer who opens an attacker-written file such as var/log/dev.log in the profiler. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

CVSS3: 5.4
0%
Низкий
16 дней назад
debian логотип
CVE-2026-45070

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-45070

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

CVSS3: 6.5
0%
Низкий
16 дней назад
debian логотип
CVE-2026-45069

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 9.1
0%
Низкий
16 дней назад

Уязвимостей на страницу


Поделиться