---
id: CVE-2026-48747
aliases:
  - GHSA-rrj9-5q2j-4gvr
title: >-
  Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the
  Request: Signature Algorithm Downgrade
summary: >-
  Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the
  Request: Signature Algorithm Downgrade
severity: medium
cwe:
  - CWE-347
  - CWE-757
vendor: symfony
product: symfony/mailomat-mailer
ecosystem: composer
affected:
  - 'symfony/mailomat-mailer >= 7.2.0, < 7.4.13'
  - 'symfony/mailomat-mailer >= 8.0.0, < 8.0.13'
  - 'symfony/symfony >= 7.2.0, < 7.4.13'
  - 'symfony/symfony >= 8.0.0, < 8.0.13'
patched:
  - symfony/mailomat-mailer 7.4.13
  - symfony/mailomat-mailer 8.0.13
  - symfony/symfony 7.4.13
  - symfony/symfony 8.0.13
published: '2026-06-15'
updated: '2026-06-15'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-rrj9-5q2j-4gvr'
references:
  - url: 'https://github.com/symfony/symfony/security/advisories/GHSA-rrj9-5q2j-4gvr'
  - url: >-
      https://github.com/symfony/symfony/commit/bdfe9fe0d94d33dfaca0bc2fe0b00b54767b0c88
  - url: >-
      https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/mailomat-mailer/CVE-2026-48747.yaml
  - url: >-
      https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2026-48747.yaml
  - url: 'https://symfony.com/cve-2026-48747'
  - url: 'https://github.com/advisories/GHSA-rrj9-5q2j-4gvr'
tags:
  - ghsa
  - composer
ingestedAt: '2026-07-07T15:41:58.732Z'
epss: 0.00247
epssPercentile: 0.16303
---

## Overview

### Description

`Symfony\Component\Mailer\Bridge\Mailomat\Webhook\MailomatRequestParser::validateSignature()` parses the `X-MOM-Webhook-Signature` request header as `algo=signature` and passes the wire-supplied `$algo` directly to `hash_hmac()` when verifying the request against the configured webhook secret. The request therefore selects the HMAC primitive used to authenticate it.

PHP's `hash_hmac()` enforces only that the chosen algorithm is HMAC-compatible. That set still includes primitives with known cryptanalysis (`md4`, `md5`, `ripemd128`, `tiger128,3`, … — e.g. existential forgery of HMAC-MD4, Contini & Yin, ASIACRYPT 2006). This is the canonical algorithm-confusion shape, analogous to JWT `alg=none` / `alg=HS256` downgrades: any future cryptographic weakness in any HMAC primitive PHP exposes becomes immediately exploitable against a Mailomat webhook receiver, the moment an attacker is in a position to compute a signature for that primitive, without a code change on the Symfony side.

Mailomat's [documented webhook security](https://api.mailomat.swiss/docs/#tag/webhook-security) pins SHA-256; the parser did not.

### Resolution

`MailomatRequestParser::validateSignature()` now requires the signature header to be of the form `sha256=<hex>` and verifies the signature with HMAC-SHA256 keyed by the configured secret using a constant-time comparison. Any other algorithm declared on the wire (including the HMAC primitives PHP would otherwise accept) is rejected.

The patch for this issue is available [here](https://github.com/symfony/symfony/commit/bdfe9fe0d94d33dfaca0bc2fe0b00b54767b0c88) for branch 7.4 (and forward-ported to 8.0 and 8.1).

### Credits

Symfony would like to thank Omar Alshammari, Essam Alanazi and Alwaleed Alshammari for reporting the issue and Nicolas Grekas for providing the fix.

## Affected packages

- `symfony/mailomat-mailer >= 7.2.0, < 7.4.13`
- `symfony/mailomat-mailer >= 8.0.0, < 8.0.13`
- `symfony/symfony >= 7.2.0, < 7.4.13`
- `symfony/symfony >= 8.0.0, < 8.0.13`

## Remediation

Upgrade to a patched release:

- `symfony/mailomat-mailer 7.4.13`
- `symfony/mailomat-mailer 8.0.13`
- `symfony/symfony 7.4.13`
- `symfony/symfony 8.0.13`
