Exposición de Symfony

Web frameworks
85
score de exposición
10.887
sitios usan
0
en explotación
1
críticos
Análisis Vexday

O histórico de vulnerabilidades catalogadas para o framework Symfony soma 24 CVEs, sem registros de exploração ativa confirmada no catálogo CISA KEV e sem entradas de severidade crítica, o que posiciona a tecnologia abaixo da média geral do catálogo em termos de taxa de exploração. Ainda assim, merece atenção o fato de que a CVE mais perigosa atualmente identificada, CVE-2024-50340, apresenta um score EPSS de aproximadamente 0,63, indicando probabilidade relevante de exploração prática em curto prazo. O tipo de falha mais recorrente é CWE-287 (autenticação inadequada), padrão que costuma facilitar acesso não autorizado quando não mitigado adequadamente. Equipes responsáveis por ambientes baseados em Symfony devem priorizar a revisão dos mecanismos de autenticação e acompanhar ativamente a evolução do risco associado a CVE-2024-50340.

CVEs

54 resultados
CVE-2026-45063CRITICALSymfony: Identity Spoofing via Unanchored DN Regex in X509AuthenticatorEPSS 0.4%CVE-2026-48784MEDIUMSymfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 NormalizationEPSS 0.3%CVE-2026-45065LOWSymfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL InjectionEPSS 0.3%CVE-2026-48761MEDIUMSymfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> contentEPSS 0.3%CVE-2026-48760MEDIUMSymfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing DefenseEPSS 0.3%CVE-2026-45066LOWSymfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> MisclassificationEPSS 0.3%CVE-2026-45064LOWSymfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href SpoofingEPSS 0.3%CVE-2026-45753LOWSymfony: HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — javascript: URI Survives Sanitization (XSS)EPSS 0.3%CVE-2024-50341LOWSecurity::login does not take into account custom user_checker in symfony/security-bundleEPSS 0.3%CVE-2026-45072LOWSymfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File RenderingEPSS 0.3%CVE-2026-45755MEDIUMSymfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event InjectionEPSS 0.3%CVE-2026-45069HIGHSymfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp ClaimsEPSS 0.3%CVE-2026-48747MEDIUMSymfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm DowngradeEPSS 0.2%CVE-2026-24739MEDIUMSymfony has incorrect argument escaping under MSYS2/Git Bash on Windows that can lead to destructive file operationsEPSS 0.2%