Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbitrarily long time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
References
| Link | Resource |
|---|---|
| https://github.com/symfony/symfony/commit/9749cd43c5e09b3735093623670b21b9d8a056cb | Patch |
| https://github.com/symfony/symfony/releases/tag/v5.4.52 | Product Release Notes |
| https://github.com/symfony/symfony/releases/tag/v6.4.40 | Product Release Notes |
| https://github.com/symfony/symfony/releases/tag/v7.4.12 | Product Release Notes |
| https://github.com/symfony/symfony/releases/tag/v8.0.12 | Product Release Notes |
| https://github.com/symfony/symfony/security/advisories/GHSA-9frc-8383-795m | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
15 Jul 2026, 14:57
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| First Time |
Sensiolabs symfony
Sensiolabs |
|
| References | () https://github.com/symfony/symfony/commit/9749cd43c5e09b3735093623670b21b9d8a056cb - Patch | |
| References | () https://github.com/symfony/symfony/releases/tag/v5.4.52 - Product, Release Notes | |
| References | () https://github.com/symfony/symfony/releases/tag/v6.4.40 - Product, Release Notes | |
| References | () https://github.com/symfony/symfony/releases/tag/v7.4.12 - Product, Release Notes | |
| References | () https://github.com/symfony/symfony/releases/tag/v8.0.12 - Product, Release Notes | |
| References | () https://github.com/symfony/symfony/security/advisories/GHSA-9frc-8383-795m - Patch, Vendor Advisory |
14 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 19:17
Updated : 2026-07-15 14:57
NVD link : CVE-2026-45305
Mitre link : CVE-2026-45305
CVE.ORG link : CVE-2026-45305
JSON object : View
Products Affected
sensiolabs
- symfony
CWE
CWE-1333
Inefficient Regular Expression Complexity
