symfony/ux-live-component vulnerabilities
CVEs whose affected-version data names the symfony/ux-live-component package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-49208Mediumux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.41%via GHSA
CVE-2026-49209Lowsymfony/ux-live-component: Denial of service via unbounded batch action requests
symfony/ux-live-component: Denial of service via unbounded batch action requests
▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.56%via GHSA
CVE-2026-49210Mediumsymfony/ux-live-component: XSS via attacker-controlled child component tag
symfony/ux-live-component: XSS via attacker-controlled child component tag
▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.34%via GHSA
CVE-2026-49212Lowsymfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.24%via GHSA
CVE-2026-49215Lowsymfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.18%via GHSA