Skip to content

« Security Advisories » blog posts

Have found a security issue in Symfony? Send the details to security [at] symfony.com and don't disclose it publicly until we can provide a fix for it.

Manage your notification preferences to receive an email as soon as a Symfony security release is published.

CVE-2024-51996: Authentication Bypass via persisted RememberMe cookie
November 13, 2024 #Security Advisories 👀 1 👍 3
Update for CVE-2024-50342: Internal address and port enumeration allowed by NoPrivateNetworkHttpClient
November 13, 2024 #Security Advisories ❤️ 1
Twig CVE-2024-51754: Unguarded calls to __toString() in a sandbox when an object is in an array or an argument list
November 6, 2024 #Security Advisories
Twig CVE-2024-51755: Unguarded calls to __isset() and to array-accesses in a sandbox
November 6, 2024 #Security Advisories 👀 1
CVE-2024-50342: Internal address and port enumeration allowed by NoPrivateNetworkHttpClient
November 6, 2024 #Security Advisories
CVE-2024-51736: Command execution hijack on Windows with Process class
November 6, 2024 #Security Advisories
CVE-2024-50340: Ability to change environment from query
November 6, 2024 #Security Advisories ❤️ 2
CVE-2024-50345: Open redirect via browser-sanitized URLs
November 6, 2024 #Security Advisories
CVE-2024-50343: Incorrect response from Validator when input ends with `\n`
November 6, 2024 #Security Advisories
CVE-2024-50341: Security::login does not take into account custom user_checker
November 6, 2024 #Security Advisories