Package impact

php COMPOSER / symfony/symfony

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2026-45063 high 8.0 9d ago Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator debianphp
CVE-2026-45067 high 8.0 9d ago Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address debianphp
CVE-2026-45077 high 8.0 9d ago Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener debianphp
CVE-2026-45066 medium 5.5 9d ago Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification debianphp
CVE-2026-45075 medium 5.5 9d ago Synfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid] debianphp
CVE-2026-45068 medium 5.5 9d ago Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address debianphp
CVE-2026-45069 medium 5.5 9d ago Symfony's OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims debianphp
CVE-2026-45070 medium 5.5 9d ago Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names debianphp
CVE-2026-45073 medium 5.5 9d ago Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix debianphp
CVE-2026-45074 medium 5.5 9d ago Symfony's Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay debianphp
CVE-2026-45064 medium 5.5 9d ago Symfony's HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing debianphp
CVE-2026-45065 medium 5.5 9d ago Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection debianphp