CVE-2026-45754

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not verify them, allowing unauthenticated POST requests to inject forged Mailjet and LOX24 event payloads. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*

History

16 Jul 2026, 03:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://github.com/symfony/symfony/commit/3e52bf5ab733ee32e35eeeeb2631d859c941838e - () https://github.com/symfony/symfony/commit/3e52bf5ab733ee32e35eeeeb2631d859c941838e - Patch
References () https://github.com/symfony/symfony/commit/4aaa45dd054f73445f1ab254968b7e60b546cc77 - () https://github.com/symfony/symfony/commit/4aaa45dd054f73445f1ab254968b7e60b546cc77 - Patch
References () https://github.com/symfony/symfony/releases/tag/v6.4.40 - () https://github.com/symfony/symfony/releases/tag/v6.4.40 - Release Notes
References () https://github.com/symfony/symfony/releases/tag/v7.4.12 - () https://github.com/symfony/symfony/releases/tag/v7.4.12 - Release Notes
References () https://github.com/symfony/symfony/releases/tag/v8.0.12 - () https://github.com/symfony/symfony/releases/tag/v8.0.12 - Release Notes
References () https://github.com/symfony/symfony/security/advisories/GHSA-64hg-93w9-fc35 - () https://github.com/symfony/symfony/security/advisories/GHSA-64hg-93w9-fc35 - Patch, Vendor Advisory
CPE cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
First Time Sensiolabs symfony
Sensiolabs

14 Jul 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 19:17

Updated : 2026-07-21 18:16


NVD link : CVE-2026-45754

Mitre link : CVE-2026-45754

CVE.ORG link : CVE-2026-45754


JSON object : View

Products Affected

sensiolabs

  • symfony
CWE
CWE-287

Improper Authentication

CWE-306

Missing Authentication for Critical Function