Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check is skipped, allowing protected controllers to execute and leak headers or perform side effects. This issue is fixed in versions 7.4.12 and 8.0.12.
References
| Link | Resource |
|---|---|
| https://github.com/symfony/symfony/releases/tag/v7.4.12 | Product Release Notes |
| https://github.com/symfony/symfony/releases/tag/v8.0.12 | Product Release Notes |
| https://github.com/symfony/symfony/security/advisories/GHSA-6439-2f28-8p8q | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
15 Jul 2026, 14:53
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* | |
| First Time |
Sensiolabs symfony
Sensiolabs |
|
| References | () https://github.com/symfony/symfony/releases/tag/v7.4.12 - Product, Release Notes | |
| References | () https://github.com/symfony/symfony/releases/tag/v8.0.12 - Product, Release Notes | |
| References | () https://github.com/symfony/symfony/security/advisories/GHSA-6439-2f28-8p8q - Patch, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
14 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 19:17
Updated : 2026-07-16 15:16
NVD link : CVE-2026-45075
Mitre link : CVE-2026-45075
CVE.ORG link : CVE-2026-45075
JSON object : View
Products Affected
sensiolabs
- symfony
CWE
CWE-863
Incorrect Authorization
