{"id":"CVE-2026-47767","aliases":["GHSA-fqc7-9xjw-jrh3"],"title":"SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch","summary":"SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch","severity":"medium","cwe":["CWE-20","CWE-74","CWE-436"],"vendor":"symfony","product":"symfony/runtime","ecosystem":"composer","affected":["symfony/runtime >= 5.4.46, < 5.4.52","symfony/runtime >= 6.4.14, < 6.4.40","symfony/runtime >= 7.1.7, < 7.4.12","symfony/runtime >= 8.0.0, < 8.0.12","symfony/symfony >= 5.4.46, < 5.4.52","symfony/symfony >= 6.4.14, < 6.4.40","symfony/symfony >= 7.1.7, < 7.4.12","symfony/symfony >= 8.0.0, < 8.0.12"],"patched":["symfony/runtime 5.4.52","symfony/runtime 6.4.40","symfony/runtime 7.4.12","symfony/runtime 8.0.12","symfony/symfony 5.4.52","symfony/symfony 6.4.40","symfony/symfony 7.4.12","symfony/symfony 8.0.12"],"published":"2026-06-09","updated":"2026-06-09","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-fqc7-9xjw-jrh3","references":[{"url":"https://github.com/symfony/symfony/security/advisories/GHSA-fqc7-9xjw-jrh3"},{"url":"https://github.com/advisories/GHSA-fqc7-9xjw-jrh3"}],"tags":["ghsa","composer"],"ingestedAt":"2026-07-07T15:41:59.599Z","epss":0.00721,"epssPercentile":0.51894,"slug":"CVE-2026-47767","body":"## Overview\n\n### Description\n\nCVE-2024-50340 (GHSA-x8vp-gf4q-mw5j) addressed an issue where, with `register_argc_argv=On`, a crafted query string let an unauthenticated GET change the kernel environment and debug flag by feeding `--env`/`--no-debug` through `$_SERVER['argv']`. The fix shipped in `symfony/runtime` 5.4.46 / 6.4.14 / 7.1.7 gated the argv read on `empty($_GET)` as a proxy for \"is this a CLI invocation\".\n\nThat proxy is unsafe: `parse_str()` (which builds `$_GET`) and the web SAPI (which builds `$_SERVER['argv']` from the raw query when `register_argc_argv=On`) do not agree on every input, so an attacker can craft a query that leaves `$_GET` empty while `$_SERVER['argv']` carries the attacker's flags. `SymfonyRuntime::getInput()` then parses them, restoring the exact primitive CVE-2024-50340 was meant to prevent.\n\nPreconditions and impact match the original CVE: web SAPI, `register_argc_argv=On`, app booted through `symfony/runtime`; from an unauthenticated GET an attacker can flip `APP_ENV` and toggle `APP_DEBUG`.\n\n### Resolution\n\n`SymfonyRuntime` now gates the argv read on `isset($_SERVER['QUERY_STRING'])` rather than on `empty($_GET)`. `QUERY_STRING` is the same input the SAPI uses to build argv, so the security check and the thing it protects no longer parse different sources. Worker SAPIs (FrankenPHP / RoadRunner / Swoole) keep working because the runtime constructor runs once at boot when `QUERY_STRING` is unset.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/3228c3806ee511008bea19a95084d460b17e5d25) for branch 5.4.\n\n### Credits\n\nSymfonyRuntime would like to thank 0xEr3n for reporting the issue and Nicolas Grekas for providing the fix.\n\n## Affected packages\n\n- `symfony/runtime >= 5.4.46, < 5.4.52`\n- `symfony/runtime >= 6.4.14, < 6.4.40`\n- `symfony/runtime >= 7.1.7, < 7.4.12`\n- `symfony/runtime >= 8.0.0, < 8.0.12`\n- `symfony/symfony >= 5.4.46, < 5.4.52`\n- `symfony/symfony >= 6.4.14, < 6.4.40`\n- `symfony/symfony >= 7.1.7, < 7.4.12`\n- `symfony/symfony >= 8.0.0, < 8.0.12`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `symfony/runtime 5.4.52`\n- `symfony/runtime 6.4.40`\n- `symfony/runtime 7.4.12`\n- `symfony/runtime 8.0.12`\n- `symfony/symfony 5.4.52`\n- `symfony/symfony 6.4.40`\n- `symfony/symfony 7.4.12`\n- `symfony/symfony 8.0.12`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}