symfony has 17 CVEs on record. Disclosures have slowed: 0 in the last 90 days after 17 in the 90 before. The busiest recent month was June 2026 with 16. The median CVSS is 7.8 (high). None have a confirmed exploitation report. The most common weakness class is CWE-79 (4). Most affected products: symfony/ux-live-component (5), symfony/html-sanitizer (2), symfony/ux-autocomplete (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 17
Weakness classes
Products
- symfony/ux-live-component 5
- symfony/html-sanitizer 2
- symfony/ux-autocomplete 2
- symfony/http-client 1
- symfony/mailomat-mailer 1
- symfony/routing 1
Worst active — by depth score
CVE-2026-24425High· 8.8Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and …49CVE-2026-55878High· 7.8symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest43CVE-2026-48489HighSymfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes41CVE-2026-55877Medium· 6.1symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses34CVE-2026-49216Mediumsymfony/ux-autocomplete: XSS via unescaped AJAX response data28
symfony vulnerabilities
CVEs affecting symfony, newest first. Open any entry for full detail, references, and exploit status.
17 CVEsRSS
CVE-2026-49208Mediumux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
CVE-2026-49209Lowsymfony/ux-live-component: Denial of service via unbounded batch action requests
symfony/ux-live-component: Denial of service via unbounded batch action requests
CVE-2026-49210Mediumsymfony/ux-live-component: XSS via attacker-controlled child component tag
symfony/ux-live-component: XSS via attacker-controlled child component tag
CVE-2026-49211Mediumsymfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
CVE-2026-49212Lowsymfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
CVE-2026-49215Lowsymfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
CVE-2026-49216Mediumsymfony/ux-autocomplete: XSS via unescaped AJAX response data
symfony/ux-autocomplete: XSS via unescaped AJAX response data
CVE-2026-55877Medium· 6.1symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses
symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses
CVE-2026-55878High· 7.8symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest
symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest
CVE-2026-48761MediumSymfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes
Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes
CVE-2026-48489HighSymfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes
Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes
CVE-2026-48736MediumSymfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
CVE-2026-48747MediumSymfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
CVE-2026-48760MediumSymfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
CVE-2026-48784MediumSymfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
CVE-2026-47767MediumSymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
CVE-2026-24425High· 8.8Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and …
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and …