Symfony Polyfill vulnerabilities
2 known vulnerabilities affecting symfony/polyfill.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-46644P3MEDIUMCVSS 6.9v>= 1.17.1, < 1.38.12026-07-14
CVE-2026-46644 [MEDIUM] CWE-1289 CVE-2026-46644: Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functio
Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33 requirement that decoded ACE labels conta
ghsanvd
CVE-2013-5958P4MEDIUMCVSS 5.0≥ 1.0.0, < 1.10.02022-05-17
CVE-2013-5958 [MEDIUM] CWE-789 Symfony Denial of Service Via Long Password Hashing
Symfony Denial of Service Via Long Password Hashing
The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to CVE-2013-5750.
ghsaosv