PatchSiren

symfony CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM symfony CVE published 2026-07-17

CVE-2026-49216

A medium-severity vulnerability was found in Symfony UX's Stimulus controller, affecting versions from 2.2.0 to 2.36.0 and 3.1.0. The issue allows attacker-controlled markup from user-supplied dropdown values to execute in the browser of any user who opens an autocomplete widget backed by the same data. This could lead to potential security risks if not properly mitigated.

LOW symfony CVE published 2026-07-17

CVE-2026-49215

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-17T17:17:16.060Z and has not been modified since then. The vulnerability affects Symfony UX versions between 2.22.0 and 2.36.0 or 3.1.0, allowing cross-origin request forgery attacks. Developers and administrators using these versions should verify and apply patches to prevent potential attacks. The [truncated]

MEDIUM symfony CVE published 2026-07-17

CVE-2026-49212

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-17T17:17:15.930Z and has not been modified since then. Symfony UX LiveComponentHydrator has a HMAC weakness allowing replay attacks. Users of Symfony UX LiveComponentHydrator should verify their installations and update to versions 2.36.0 or 3.1.0.

MEDIUM symfony CVE published 2026-07-17

CVE-2026-49211

CVE-2026-49211 is a SQL injection vulnerability in Symfony UX Autocomplete endpoint. The issue was fixed in versions 2.36.0 and 3.1.0. This vulnerability allows unauthenticated users to turn the public BaseEntityAutocompleteType endpoint into a broad matcher or blind boolean oracle against every column in default searchable_fields. Users of Symfony UX Autocomplete endpoint should apply the patches to prev [truncated]

LOW symfony CVE published 2026-07-17

CVE-2026-49210

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-17T17:17:15.650Z and has not been modified since then. This vulnerability affects Symfony UX versions between 2.8.0 and 2.36.0 or 3.1.0, allowing client-controlled input to be directly interpolated into HTML as a tag name without proper escaping or validation. This could lead to arbitrary HTML injec [truncated]

MEDIUM symfony CVE published 2026-07-17

CVE-2026-49209

CVE-2026-49209 is a denial of service vulnerability in Symfony UX LiveComponent BatchActionController. An authenticated client can submit a single _batch request containing thousands of actions and exhaust CPU, memory, and database connections on the application server. This issue affects users of Symfony UX LiveComponent version 2.5.0 through 2.36.0 and 3.1.0.

MEDIUM symfony CVE published 2026-07-17

CVE-2026-49208

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-17T17:17:15.380Z and has not been modified since then. Symfony UX, a JavaScript ecosystem for Symfony, has a security vulnerability in LiveComponentHydrator when handling DateTimeInterface types without explicit formats. This allows client-supplied relative strings like 'now' or '+10 years' to move [truncated]

HIGH symfony CVE published 2026-07-14

CVE-2026-45075

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T19:17:06.650Z and has not been modified since then. Symfony, a PHP framework for web and console applications, had method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes that could be configured for GET requests only. However, Symfony routes HEAD requests to the GET h [truncated]

LOW symfony CVE published 2026-07-14

CVE-2026-45072

The CVE record for CVE-2026-45072 was published on 2026-07-14T19:17:06.277Z and has not been modified since then. The NVD entry is currently Analyzed. This CVE is for a stored XSS vulnerability in the development profiler of Symfony, a PHP framework for web and console applications. The vulnerability exists in versions 6.4.24 through 6.4.40, 7.4.12, and 8.0.12 due to the file_excerpt Twig filter's behavio [truncated]

LOW symfony CVE published 2026-07-14

CVE-2026-45066

CVE-2026-45066 is a low-severity vulnerability in Symfony's HtmlSanitizer component. The issue allows off-allowlist URLs to pass through certain methods, such as allowLinkHosts() or allowMediaHosts(), due to differences in URL parsing between UrlSanitizer::parse() and browser behavior. This vulnerability affects Symfony versions from 6.1.0-BETA1 to 6.4.40, 7.4.12, and 8.0.12. The issue is fixed in version [truncated]

MEDIUM symfony CVE published 2026-07-08

CVE-2026-55877

A cross-site scripting vulnerability exists in Symfony UX, a JavaScript ecosystem for Symfony. The vulnerability affects versions 2.17.0 before 2.36.1 and 3.0.0 before 3.2.0. The ux_icon() Twig function is marked as is_safe=['html'] and Icon::toHtml() inlines SVG source verbatim, allowing unsanitized local SVG files or Iconify on-demand JSON body responses containing nested script elements, on* event hand [truncated]