HIGH🇵🇱 Wersja polska

CVE-2026-45305

CVSS 8.7v4.0pub. 2026-07-14upd. 2026-07-15

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbitrarily long time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sensiolabs Symfony

    APP
    Sensiolabs
    < 5.4.526.0.0 – 6.4.40 (excl.)7.0.0 – 7.4.12 (excl.)8.0.0 – 8.0.12 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-45063CRITICAL9.1PL ✓same product

Symfony X509Authenticator — obejście uwierzytelniania przez błędny regex DN

CVE-2019-11325CRITICAL9.8PL ✓same product

Symfony VarExporter — nieprawidłowe escapowanie umożliwia RCE

CVE-2019-18889CRITICAL9.8PL ✓same product

Symfony: zdalne wykonanie kodu przez serializację adaptera cache

CVE-2017-11365CRITICAL9.8PL ✓same product

Nieprawidłowa kontrola dostępu w komponencie Password validator — Symfony

CVE-2019-10910CRITICAL9.8PL ✓same product

SQL Injection i RCE w Symfony przez niezwalidowane identyfikatory serwisów