PatchSiren

Sensiolabs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Sensiolabs CVE published 2026-07-14

CVE-2026-48736

The CVE record for CVE-2026-48736 was published on 2026-07-14T20:17:09.943Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Symfony framework versions 5.4.0 to 5.4.53, 6.4.0 to 6.4.41, 7.0.0 to 7.4.13, and 8.0.0 to 8.0.13, allowing attacker-supplied URLs to represent private IPv4 targets. The vulnerability is classified as a medium priority due to its [truncated]

HIGH Sensiolabs CVE published 2026-07-14

CVE-2026-48489

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T20:17:09.330Z and has not been modified since then. This vulnerability affects Symfony framework versions prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, allowing an unauthenticated attacker to dispatch a subrequest to access_control-protected GET routes that skipped firewall listeners when failure_ [truncated]

HIGH Sensiolabs CVE published 2026-07-14

CVE-2026-47767

A high-severity vulnerability was found in Symfony, a PHP framework for web and console applications. The issue, tracked as CVE-2026-47767, allows attackers to execute code via crafted query strings. It exists in versions 5.4.46 through 5.4.52, 6.4.40, 7.4.12, and 8.0.12. The vulnerability is caused by a disagreement between parse_str() and the web SAPI, allowing a crafted query string to leave $_GET empt [truncated]

MEDIUM Sensiolabs CVE published 2026-07-14

CVE-2026-45754

The Symfony framework, widely used for web and console applications, had a vulnerability in its Mailjet mailer bridge and LOX24 notifier bridge. Prior to versions 6.4.40, 7.4.12, and 8.0.12, these bridges did not verify configured webhook secrets. This oversight allowed unauthenticated POST requests to inject forged Mailjet and LOX24 event payloads. The issue has been addressed in Symfony versions 6.4.40, [truncated]

MEDIUM Sensiolabs CVE published 2026-07-14

CVE-2026-45070

The CVE record for CVE-2026-45070 was published on 2026-07-14T19:17:06.147Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Symfony framework versions prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, allowing for potential header injection attacks through the ParameterizedHeader component. Users of these versions should apply patches to prevent potential h [truncated]

LOW Sensiolabs CVE published 2026-07-14

CVE-2026-45064

The CVE record describes a visual spoofing vulnerability in Symfony's UrlSanitizer. From versions 6.1.0-BETA1 to 6.4.40, 7.4.12, and 8.0.12, the UrlSanitizer::parse() method fails to remove Unicode explicit-direction BiDi formatting characters from sanitized href and src attributes. This allows attackers to create links that visually appear to point to a different destination than the actual link target, [truncated]

HIGH Sensiolabs CVE published 2026-07-14

CVE-2026-45756

CVE-2026-45756 is a high-severity denial-of-service vulnerability in the Symfony PHP framework. The vulnerability exists in the JsonPath component, where attacker-controlled match() and search() filter patterns are compiled directly into preg_match() without proper restrictions, allowing for catastrophic backtracking expressions that can pin worker CPU. This issue affects Symfony versions 7.3.0-BETA1 thro [truncated]

CRITICAL Sensiolabs CVE published 2017-02-07

CVE-2016-2403

CVE-2016-2403 is a critical authentication-bypass issue in Symfony. On affected versions, a remote attacker with a valid username could authenticate using an empty password when the application was configured against a misconfigured LDAP server, resulting in an unauthenticated bind and possible full account compromise. NVD rates the issue CVSS 9.8 and maps it to CWE-287.