cbcvebase.
CVE-2026-45075
published 2026-07-14

CVE-2026-45075: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted]…

PriorityP351high8.2CVSS 3.1
AVNACLPRNUINSUCLIHAN
EPSS
0.38%
30.6th percentile
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check is skipped, allowing protected controllers to execute and leak headers or perform side effects. This issue is fixed in versions 7.4.12 and 8.0.12.

Affected

14 ranges
VendorProductVersion rangeFixed in
sensiolabssymfony>= 7.4.0 < 7.4.127.4.12
sensiolabssymfony>= 8.0.0 < 8.0.128.0.12
symfonyhttp-kernel
symfonyhttp-kernel
symfonyhttp-kernel>= 7.4.0 < 7.4.127.4.12
symfonyhttp-kernel>= 8.0.0 < 8.0.128.0.12
symfonysecurity-http
symfonysecurity-http
symfonysecurity-http>= 7.4.0 < 7.4.127.4.12
symfonysecurity-http>= 8.0.0 < 8.0.128.0.12
symfonysymfony
symfonysymfony
symfonysymfony>= 7.4.0 < 7.4.127.4.12
symfonysymfony>= 8.0.0 < 8.0.128.0.12

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
nvdv4.08.3HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.