api-platform/core vulnerabilities
CVEs whose affected-version data names the api-platform/core package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54164Medium· 6.5API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
▾ Sunlitapi-platform · api-platform/coreEPSS 0.34%via GHSA
CVE-2026-49858Medium· 5.9API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
▾ Sunlitapi-platform · api-platform/coreEPSS 0.32%via GHSA