FAD-Checker Report

Multi-ecosystem dependency security audit
Project: multi-cms-frameworks
Generated: 2026-09-24T16:41:13.974Z · fad-checker 2.7.1
CRITICAL Executive Summary
251 dependencies scanned
Top 3 most critical · direct production dependencies
Top 2 end-of-life frameworks
Everything else: 201 production CVE (critical=8, high=57, medium=99, low=37) · 8 dev/test CVE · 44 vulnerable vendored-JS · 5 EOL frameworks · 12 obsolete · 215 outdated · 24 scan alerts
8
Critical
57
High
99
Medium
37
Low
2
KEV exploited
201
Total CVEs
201
in Direct
0
in Transitive
44
Vendored JS
5
EOL
12
Obsolete
215
Outdated
4
Licenses to review
24
Scan alerts
CWE — direct vulns (by criticality)CWE-601 — URL Redirection to Untrusted Site (Open Redirect): 4CWE-79 — Cross-site Scripting (XSS): 3CWE-93 — CRLF Injection: 3CWE-1333 — Inefficient Regular Expression Complexity (ReDoS): 2CWE-20 — Improper Input Validation: 2CWE-287 — Improper Authentication: 2CWE-290 — Authentication Bypass by Spoofing: 2__more__: 25CWE-601 — Medium: 3/4 (75%)CWE-601 — Low: 1/4 (25%)CWE-79 — Medium: 3/3 (100%)CWE-93 — High: 2/3 (67%)CWE-93 — Medium: 1/3 (33%)CWE-1333 — Low: 2/2 (100%)CWE-20 — Critical: 1/2 (50%)CWE-20 — Low: 1/2 (50%)CWE-287 — High: 1/2 (50%)CWE-287 — Low: 1/2 (50%)CWE-290 — High: 1/2 (50%)CWE-290 — Medium: 1/2 (50%)__more__ — Critical: 1/25 (4%)__more__ — High: 8/25 (32%)__more__ — Medium: 11/25 (44%)__more__ — Low: 5/25 (20%)43CriticalHighMediumLowCWE-601 · URL Redirection to Untrusted Site (Open Redirect) · 4CWE-79 · Cross-site Scripting (XSS) · 3CWE-93 · CRLF Injection · 3CWE-1333 · Inefficient Regular Expression Complexity (ReDoS) · 2CWE-20 · Improper Input Validation · 2CWE-287 · Improper Authentication · 2CWE-290 · Authentication Bypass by Spoofing · 2__more__ · 25
Indirect CVEs per direct dependencycore Drupal: 57framework laravel/framework: 38framework symfony/framework-bundle: 27framework-component laravel/socialite: 18framework-component symfony/debug-bundle: 18bundle symfony/stimulus-bundle: 18framework-component symfony/twig-bridge: 18+6 more: 57core Drupal — Critical: 3/57 (5%)core Drupal — High: 17/57 (30%)core Drupal — Medium: 26/57 (46%)core Drupal — Low: 11/57 (19%)framework laravel/framework — Critical: 2/38 (5%)framework laravel/framework — High: 14/38 (37%)framework laravel/framework — Medium: 18/38 (47%)framework laravel/framework — Low: 4/38 (11%)framework symfony/framework-bundle — High: 8/27 (30%)framework symfony/framework-bundle — Medium: 14/27 (52%)framework symfony/framework-bundle — Low: 5/27 (19%)framework-component laravel/socialite — High: 3/18 (17%)framework-component laravel/socialite — Medium: 13/18 (72%)framework-component laravel/socialite — Low: 2/18 (11%)framework-component symfony/debug-bundle — Critical: 1/18 (6%)framework-component symfony/debug-bundle — High: 5/18 (28%)framework-component symfony/debug-bundle — Medium: 6/18 (33%)framework-component symfony/debug-bundle — Low: 6/18 (33%)bundle symfony/stimulus-bundle — Critical: 1/18 (6%)bundle symfony/stimulus-bundle — High: 5/18 (28%)bundle symfony/stimulus-bundle — Medium: 6/18 (33%)bundle symfony/stimulus-bundle — Low: 6/18 (33%)framework-component symfony/twig-bridge — Critical: 1/18 (6%)framework-component symfony/twig-bridge — High: 5/18 (28%)framework-component symfony/twig-bridge — Medium: 6/18 (33%)framework-component symfony/twig-bridge — Low: 6/18 (33%)+6 more — Critical: 3/57 (5%)+6 more — High: 15/57 (26%)+6 more — Medium: 19/57 (33%)+6 more — Low: 20/57 (35%)251CriticalHighMediumLowcore Drupal · 57framework laravel/framework · 38framework symfony/framework-bundle · 27framework-component laravel/socialite · 18framework-component symfony/debug-bundle · 18bundle symfony/stimulus-bundle · 18framework-component symfony/twig-bridge · 18+6 more · 57
Most vulnerable instancesdrupal · drupal: 23laravel · bookstack: 21symfony · symfony-demo: 21drupal · drupal — Critical: 5/23 (22%)drupal · drupal — High: 18/23 (78%)laravel · bookstack — Critical: 2/21 (10%)laravel · bookstack — High: 19/21 (90%)symfony · symfony-demo — Critical: 1/21 (5%)symfony · symfony-demo — High: 20/21 (95%)65CriticalHighdrupal · drupal · 23laravel · bookstack · 21symfony · symfony-demo · 21Critical/high application findings per exposed instance — a shared occurrence counts in each. 1 advisory check(s) incomplete.
Fix priorityExploited: 2Critical: 3High: 47Medium: 122Low: 27201Exploited · 2Critical · 3High · 47Medium · 122Low · 27
Click a section header or a CVE row to toggle.

0. Warnings & scan-completeness (24)

⚠️ Manifests without a lockfile — best-effort (ranges skipped) (24)
  • drupal/core/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 40 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Annotation/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 5 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Assertion/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 0 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Bridge/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 1 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/ClassFinder/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 1 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Datetime/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 1 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/DependencyInjection/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 1 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Diff/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 1 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Discovery/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 2 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/EventDispatcher/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 2 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/FileCache/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 0 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/FileSystem/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 0 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Gettext/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 1 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Graph/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 0 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/HttpFoundation/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 1 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/PhpStorage/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 0 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Plugin/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 1 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/ProxyBuilder/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 0 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Render/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 1 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Serialization/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 1 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Transliteration/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 0 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Utility/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 2 range(s) skipped (run "composer install")
  • drupal/core/lib/Drupal/Component/Uuid/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 1 range(s) skipped (run "composer install")
  • wp/wp-includes/sodium_compat/composer.json
    composer.json without composer.lock — best-effort: 0 pinned, 2 range(s) skipped (run "composer install")

1. CVE (201 direct, 0 indirect, 8 dev)

1.1 CMS & Frameworks (209)

209 unique physical finding(s); 209 application exposure(s).
Application directness uses proven component ownership; overview charts use package-manager scope. A shared physical occurrence is counted once.

Instance synthesis (4)

CMS / frameworkInstanceObserved versionDirectIndirectUnknown originPriorityCoverageNote
drupaldrupal8.5.016610EXPLOITED · 9.8inventory: completed (1/1), advisories (drupal-security-advisories): completed (1/1)
laravelbookstack10.48.224600CRITICALinventory: completed (147/147), advisories (dependency-lanes): completed (147/147)
symfonysymfony-demo7.1.122460HIGH · 8.8inventory: completed (118/118), advisories (dependency-lanes): completed (118/118), recipes: completed (110/110)
wordpresswp6.4.2000—inventory: completed (15/15), advisories (wordfence-v3): not-run (0/15, 15 not evaluated — CMS_PROVIDER_UNCONFIGURED), integrity (wordpress-checksums): completed (2960/2960)Evaluation incomplete.

Production (201)

drupal · drupal (73)

core Drupal 8.5.0 (73)

Direct (16)

Priority / severityAdvisory IDDependencyCWEDescriptionFix VersionSource
EXPLOITED
🛑 KEV · ransomware
CRITICAL 9.8
EPSS: 100%
Published: 2018-03-28
CVE-2018-7600
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-20
Improper Input Validation
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations. 8.5.1 drupal-security-advisoriesnvd
Description
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
Weaknesses (CWE) (1)
  • CWE-20 — Improper Input Validation
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 (CRITICAL)
EXPLOITED · 98.4/100
100.0% prob · 100th pct
Known exploited · added 2021-11-03 · due 2022-05-03 · ransomware
8.5.1
2018-03-28
2026-06-17
probable
drupal-security-advisories+nvd
Highly critical (Drupal)
Affected CPE configurations (7)
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Aliases
EXPLOITED
🛑 KEV · ransomware
CRITICAL 9.8
EPSS: 100%
Published: 2018-04-25
CVE-2018-7602
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-94
Code Injection
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. 8.5.3 drupal-security-advisoriesnvd
Description
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 (CRITICAL)
EXPLOITED · 98.4/100
99.2% prob · 100th pct
Known exploited · added 2022-04-13 · due 2022-05-04 · ransomware
8.5.3
2018-04-25
2026-08-13
probable
drupal-security-advisories+nvd
Highly critical (Drupal)
Affected CPE configurations (6)
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Aliases
MEDIUM
HIGH 7.5
EPSS: 40%
Published: 2024-01-17
CVE-2024-11941
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-835
Loop with Unreachable Exit Condition (Infinite Loop)
A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8. 10.1.8 drupal-security-advisoriesnvd
Description
A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.
Weaknesses (CWE) (1)
  • CWE-835 — Loop with Unreachable Exit Condition (Infinite Loop)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
MEDIUM · 68.1/100
0.5% prob · 40th pct
10.1.8
2024-01-17
2026-06-17
probable
drupal-security-advisories+nvd
Moderately critical (Drupal)
External links (1)
Affected CPE configurations (2)
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Aliases
MEDIUM
MEDIUM 6.1
EPSS: 77%
Published: 2018-04-18
CVE-2018-9861
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-79
Cross-site Scripting (XSS)
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote at… 8.5.2 drupal-security-advisoriesnvd
Description
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.
Weaknesses (CWE) (1)
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 (MEDIUM)
MEDIUM · 64.2/100
1.8% prob · 77th pct
8.5.2
2018-04-18
2026-06-17
probable
drupal-security-advisories+nvd
Moderately critical (Drupal)
Affected CPE configurations (3)
  • cpe:2.3:a:ckeditor:enhanced_image:*:*:*:*:*:ckeditor:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Aliases
MEDIUM
MEDIUM 6.5
EPSS: 44%
Published: 2023-04-19
CVE-2023-31250
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-863
Incorrect Authorization
The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files that they should not have access to. 9.4.14 drupal-security-advisoriesnvd
Description
The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files that they should not have access to. Some sites may require configuration changes following this security release. Review the release notes for your Drupal version if you have issues accessing private files after updating.
Weaknesses (CWE) (1)
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
6.5 (MEDIUM)
MEDIUM · 60.9/100
0.5% prob · 44th pct
9.4.14
2023-04-19
2026-06-17
probable
drupal-security-advisories+nvd
Moderately critical (Drupal)
External links (1)
Affected CPE configurations (4)
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Aliases
MEDIUM
MEDIUM 5.9
EPSS: 29%
Published: 2026-06-17
CVE-2026-55803
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-915
Mass Assignment
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. 10.5.12 drupal-security-advisoriesnvd
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
5.9 (MEDIUM)
MEDIUM · 53/100
0.4% prob · 29th pct
10.5.12
2026-06-17
2026-07-16
probable
drupal-security-advisories+nvd
Critical (Drupal)
External links (1)
Affected CPE configurations (4)
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Aliases
MEDIUM
MEDIUM 5.9
EPSS: 29%
Published: 2026-06-17
CVE-2026-55804
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-915
Mass Assignment
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. 10.5.12 drupal-security-advisoriesnvd
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
5.9 (MEDIUM)
MEDIUM · 53/100
0.4% prob · 29th pct
10.5.12
2026-06-17
2026-07-16
probable
drupal-security-advisories+nvd
Moderately critical (Drupal)
External links (1)
Affected CPE configurations (4)
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Aliases
MEDIUM
MEDIUM 5.9
EPSS: 27%
Published: 2026-06-17
CVE-2026-55806
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-601
URL Redirection to Untrusted Site (Open Redirect)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. 10.5.12 drupal-security-advisoriesnvd
Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Weaknesses (CWE) (1)
  • CWE-601 — URL Redirection to Untrusted Site (Open Redirect)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
5.9 (MEDIUM)
MEDIUM · 52.7/100
0.3% prob · 27th pct
10.5.12
2026-06-17
2026-07-16
probable
drupal-security-advisories+nvd
Less critical (Drupal)
External links (1)
Affected CPE configurations (4)
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Aliases
MEDIUM
MEDIUM
Published: 2023-01-18
SA-CORE-2023-001
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
— Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-001 9.4.10 drupal-security-advisories
Description
Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-001
Metadata
MEDIUM · 50/100
9.4.10
2023-01-18
probable
drupal-security-advisories
Moderately critical (Drupal)
External links (1)
Security advisory1 link
Aliases
  • SA-CORE-2023-001
MEDIUM
MEDIUM
Published: 2023-03-15
SA-CORE-2023-002
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
— Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-002 9.4.12 drupal-security-advisories
Description
Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-002
Metadata
MEDIUM · 50/100
9.4.12
2023-03-15
probable
drupal-security-advisories
Moderately critical (Drupal)
External links (1)
Security advisory1 link
Aliases
  • SA-CORE-2023-002
MEDIUM
MEDIUM
Published: 2023-03-15
SA-CORE-2023-003
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
— Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-003 9.4.12 drupal-security-advisories
Description
Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-003
Metadata
MEDIUM · 50/100
9.4.12
2023-03-15
probable
drupal-security-advisories
Moderately critical (Drupal)
External links (1)
Security advisory1 link
Aliases
  • SA-CORE-2023-003
MEDIUM
MEDIUM
Published: 2023-03-15
SA-CORE-2023-004
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
— Drupal core - Moderately critical - Access bypass - SA-CORE-2023-004 9.4.12 drupal-security-advisories
Description
Drupal core - Moderately critical - Access bypass - SA-CORE-2023-004
Metadata
MEDIUM · 50/100
9.4.12
2023-03-15
probable
drupal-security-advisories
Moderately critical (Drupal)
External links (1)
Security advisory1 link
Aliases
  • SA-CORE-2023-004
MEDIUM
MEDIUM 5.4
EPSS: 20%
Published: 2026-06-17
CVE-2026-55808
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-79
Cross-site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). 10.5.12 drupal-security-advisoriesnvd
Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Weaknesses (CWE) (1)
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
5.4 (MEDIUM)
MEDIUM · 47.2/100
0.3% prob · 20th pct
10.5.12
2026-06-17
2026-07-16
probable
drupal-security-advisories+nvd
Moderately critical (Drupal)
External links (1)
Affected CPE configurations (4)
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Aliases
MEDIUM
MEDIUM 5.4
EPSS: 3%
Published: 2026-07-15
CVE-2026-55805
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-79
Cross-site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. 10.6.13 drupal-security-advisoriesnvd
Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
Weaknesses (CWE) (1)
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
5.4 (MEDIUM)
MEDIUM · 43.8/100
0.1% prob · 3th pct
10.6.13
2026-07-15
2026-08-28
probable
drupal-security-advisories+nvd
Moderately critical (Drupal)
External links (1)
Aliases
LOW
MEDIUM 4.2
EPSS: 2%
Published: 2026-07-15
CVE-2026-15916
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-862
Missing Authorization
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. 10.6.13 drupal-security-advisoriesnvd
Description
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
Weaknesses (CWE) (1)
  • CWE-862 — Missing Authorization
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
4.2 (MEDIUM)
LOW · 34.1/100
0.1% prob · 2th pct
10.6.13
2026-07-15
2026-08-28
probable
drupal-security-advisories+nvd
Moderately critical (Drupal)
External links (1)
Aliases
LOW
LOW 3.1
EPSS: 13%
Published: 2026-06-17
CVE-2026-55807
probable
composer:
drupal/core
8.5.0 direct
defined in: drupal/core/lib/Drupal.php
CWE-918
Server-Side Request Forgery (SSRF)
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. 10.5.12 drupal-security-advisoriesnvd
Description
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Weaknesses (CWE) (1)
  • CWE-918 — Server-Side Request Forgery (SSRF)
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
3.1 (LOW)
LOW · 27.4/100
0.2% prob · 13th pct
10.5.12
2026-06-17
2026-07-16
probable
drupal-security-advisories+nvd
Moderately critical (Drupal)
External links (1)
Affected CPE configurations (4)
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Aliases

Indirect (57)

Priority / severityAdvisory IDDependencyCWEDescriptionFix VersionSource
CRITICAL
CRITICAL 9.8
EPSS: 93%
Published: 2019-04-16
CVE-2019-10910
exact
composer:
symfony/dependency-injection
3.4.4 direct
defined in: drupal/drupal
CWE-89
SQL Injection
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. 3.4.26 nvdosvpackagist
Description
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 (CRITICAL)
CRITICAL · 97/100
5.9% prob · 93th pct
3.4.26
2019-04-16
2025-05-29
exact
nvd+osv+packagist
Affected CPE configurations (7)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
CRITICAL
CRITICAL 9.8
EPSS: 78%
Published: 2019-04-16
CVE-2019-10913
exact
composer:
symfony/http-foundation
3.4.4 direct
defined in: drupal/drupal
CWE-79
Cross-site Scripting (XSS)
CWE-89
SQL Injection
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly c… 3.4.26 nvdosvpackagist
Description
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
Weaknesses (CWE) (2)
  • CWE-79 — Cross-site Scripting (XSS)
  • CWE-89 — SQL Injection
Metadata
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 (CRITICAL)
CRITICAL · 94.1/100
1.9% prob · 78th pct
3.4.26
2019-04-16
2023-11-08
exact
nvd+osv+packagist
Affected CPE configurations (5)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
CRITICAL 8.7
EPSS: 51%
Published: 2026-05-20
CVE-2026-46633
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-94
Code Injection
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to termin… 2.0.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (CRITICAL)
HIGH · 79.9/100
0.7% prob · 51th pct
2.0.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
LOW 8.7
EPSS: 51%
Published: 2026-05-20
CVE-2026-45304
exact
composer:
symfony/yaml
3.4.5 direct
defined in: drupal/drupal
CWE-776
XML Entity Expansion (XEE / Billion Laughs)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 4.0.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small untrusted YAML input to expand into a multi-gigabyte structure and exhaust memory. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
  • CWE-776 — XML Entity Expansion (XEE / Billion Laughs)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (LOW)
HIGH · 79.8/100
0.7% prob · 51th pct
4.0.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
LOW 8.7
EPSS: 51%
Published: 2026-05-20
CVE-2026-45305
exact
composer:
symfony/yaml
3.4.5 direct
defined in: drupal/drupal
CWE-1333
Inefficient Regular Expression Complexity (ReDoS)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 4.0.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbitrarily long time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
  • CWE-1333 — Inefficient Regular Expression Complexity (ReDoS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (LOW)
HIGH · 79.8/100
0.7% prob · 51th pct
4.0.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
MEDIUM 8.5
EPSS: 57%
Published: 2024-09-09
CVE-2024-45411
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-693
Protection Mechanism Failure
Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0. 1.44.7 nvdosvpackagist
Description
Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.
Weaknesses (CWE) (1)
  • CWE-693 — Protection Mechanism Failure
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
8.5 (MEDIUM)
HIGH · 79.3/100
0.8% prob · 57th pct
1.44.7
2024-09-09
2024-10-10
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 8.1
EPSS: 70%
Published: 2019-11-13
CVE-2019-18887
exact
composer:
symfony/http-kernel
3.4.4 direct
defined in: drupal/drupal
CWE-203
Observable Discrepancy
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel. 3.4.35 nvdosvpackagist
Description
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
Weaknesses (CWE) (1)
  • CWE-203 — Observable Discrepancy
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
8.1 (HIGH)
HIGH · 78.8/100
1.3% prob · 70th pct
3.4.35
2019-11-13
2024-02-20
exact
nvd+osv+packagist
Affected CPE configurations (6)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 8.0
EPSS: 70%
Published: 2022-05-25
CVE-2022-29248
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-565
Reliance on Cookies without Validation and Integrity Checking
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. 6.5.6 nvdosvpackagist
Description
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the Set-Cookie header, allowing a malicious server to set cookies for unrelated domains. The cookie middleware is disabled by default, so most library consumers will not be affected by this issue. Only those who manually add the cookie middleware to the handler stack or construct the client with ['cookies' => true] are affected. Moreover, those who do not use the same Guzzle client to call multiple domains and have disabled redirect forwarding are not affected by this vulnerability. Guzzle versions 6.5.6 and 7.4.3 contain a patch for this issue. As a workaround, turn off the cookie middleware.
Weaknesses (CWE) (2)
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-565 — Reliance on Cookies without Validation and Integrity Checking
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
8.0 (HIGH)
HIGH · 78/100
1.3% prob · 70th pct
6.5.6
2022-05-25
2025-12-10
exact
nvd+osv+packagist
Affected CPE configurations (5)
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 7.7
EPSS: 79%
Published: 2022-06-20
CVE-2022-31090
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. 6.5.8 nvdosvpackagist
Description
Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` header. On making a request which responds with a redirect to a URI with a different origin (change in host, scheme or port), if we choose to follow it, we should remove the `CURLOPT_HTTPAUTH` option before continuing, stopping curl from appending the `Authorization` header to the new request. Affected Guzzle 7 users should upgrade to Guzzle 7.4.5 as soon as possible. Affected users using any earlier series of Guzzle should upgrade to Guzzle 6.5.8 or 7.4.5. Note that a partial fix was implemented in Guzzle 7.4.2, where a change in host would trigger removal of the curl-added Authorization header, however this earlier fix did not cover change in scheme or change in port. If you do not require or expect redirects to be followed, one should simply disable redirects all together. Alternatively, one can specify to use the Guzzle steam handler backend, rather than curl.
Weaknesses (CWE) (2)
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-212 — Improper Removal of Sensitive Information Before Storage or Transfer
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
7.7 (HIGH)
HIGH · 77.4/100
1.9% prob · 79th pct
6.5.8
2022-06-20
2024-02-16
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 7.5
EPSS: 84%
Published: 2022-09-28
CVE-2022-39261
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-22
Path Traversal
Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. 1.44.7 nvdosvpackagist
Description
Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `include` statement to read arbitrary files from outside the templates' directory when using a namespace like `@somewhere/../some.file`. In such a case, validation is bypassed. Versions 1.44.7, 2.15.3, and 3.4.3 contain a fix for validation of such template names. There are no known workarounds aside from upgrading.
Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
7.5 (HIGH)
HIGH · 76.9/100
2.6% prob · 84th pct
1.44.7
2022-09-28
2025-12-10
exact
nvd+osv+packagist
Affected CPE configurations (10)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 7.5
EPSS: 82%
Published: 2019-11-13
CVE-2019-18888
exact
composer:
symfony/http-foundation
3.4.4 direct
defined in: drupal/drupal
CWE-88
Argument Injection
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. 3.4.35 nvdosvpackagist
Description
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x).
Weaknesses (CWE) (1)
  • CWE-88 — Argument Injection
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
7.5 (HIGH)
HIGH · 76.4/100
2.2% prob · 82th pct
3.4.35
2019-11-13
2024-02-20
exact
nvd+osv+packagist
Affected CPE configurations (6)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 7.7
EPSS: 74%
Published: 2022-06-20
CVE-2022-31091
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. 6.5.8 nvdosvpackagist
Description
Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a redirect to a URI with a different port, if we choose to follow it, we should remove the `Authorization` and `Cookie` headers from the request, before containing. Previously, we would only consider a change in host or scheme. Affected Guzzle 7 users should upgrade to Guzzle 7.4.5 as soon as possible. Affected users using any earlier series of Guzzle should upgrade to Guzzle 6.5.8 or 7.4.5. Note that a partial fix was implemented in Guzzle 7.4.2, where a change in host would trigger removal of the curl-added Authorization header, however this earlier fix did not cover change in scheme or change in port. An alternative approach would be to use your own redirect middleware, rather than ours, if you are unable to upgrade. If you do not require or expect redirects to be followed, one should simply disable redirects all together.
Weaknesses (CWE) (1)
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
7.7 (HIGH)
HIGH · 76.3/100
1.5% prob · 74th pct
6.5.8
2022-06-20
2023-11-08
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 7.5
EPSS: 79%
Published: 2022-06-09
CVE-2022-31042
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. 6.5.7 nvdosvpackagist
Description
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, or on making a request to a server which responds with a redirect to a a URI to a different host, we should not forward the `Cookie` header on. Prior to this fix, only cookies that were managed by our cookie middleware would be safely removed, and any `Cookie` header manually added to the initial request would not be stripped. We now always strip it, and allow the cookie middleware to re-add any cookies that it deems should be there. Affected Guzzle 7 users should upgrade to Guzzle 7.4.4 as soon as possible. Affected users using any earlier series of Guzzle should upgrade to Guzzle 6.5.7 or 7.4.4. Users unable to upgrade may consider an alternative approach to use your own redirect middleware, rather than ours. If you do not require or expect redirects to be followed, one should simply disable redirects all together.
Weaknesses (CWE) (2)
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-212 — Improper Removal of Sensitive Information Before Storage or Transfer
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
7.5 (HIGH)
HIGH · 75.8/100
1.9% prob · 79th pct
6.5.7
2022-06-09
2025-12-10
exact
nvd+osv+packagist
Affected CPE configurations (8)
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:9.4.0:alpha1:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:9.4.0:beta1:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:9.4.0:rc1:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 8.7
EPSS: 30%
Published: 2026-05-27
CVE-2026-46636
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-1336 Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. 2.0.0 nvdpackagist
Description
Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (HIGH)
HIGH · 75.5/100
0.4% prob · 30th pct
2.0.0
2026-05-27
2026-09-08
exact
nvd+packagist
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
LOW 8.2
EPSS: 49%
Published: 2026-05-20
CVE-2026-45133
exact
composer:
symfony/yaml
3.4.5 direct
defined in: drupal/drupal
CWE-674
Uncontrolled Recursion
CWE-776
XML Entity Expansion (XEE / Billion Laughs)
+1
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 4.0.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parsers to recurse without a depth limit. A crafted document exhausts the PHP stack and crashes the worker. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (3)
  • CWE-674 — Uncontrolled Recursion
  • CWE-776 — XML Entity Expansion (XEE / Billion Laughs)
  • CWE-1333 — Inefficient Regular Expression Complexity (ReDoS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.2 (LOW)
HIGH · 75.4/100
0.6% prob · 49th pct
4.0.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH
Published: 2018-06-11
GHSA-f6p5-76fp-m248
exact
composer:
zendframework/zend-diactoros
1.4.1 direct
defined in: drupal/drupal
— URL Rewrite vulnerability in multiple zendframework components zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each co… 1.8.4 osvpackagist
Description
URL Rewrite vulnerability in multiple zendframework components zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism. When these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content.
Metadata
HIGH · 75/100
1.8.4
2018-06-11
2024-11-28
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH
Published: 2018-06-11
GHSA-f6p5-76fp-m248
exact
composer:
zendframework/zend-feed
2.7.0 direct
defined in: drupal/drupal
— URL Rewrite vulnerability in multiple zendframework components zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each co… 2.10.3 osvpackagist
Description
URL Rewrite vulnerability in multiple zendframework components zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism. When these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content.
Metadata
HIGH · 75/100
2.10.3
2018-06-11
2024-11-28
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 7.5
Published: 2024-06-07
GHSA-jmmp-vh96-78rm
exact
composer:
zendframework/zend-feed
2.7.0 direct
defined in: drupal/drupal
— Zend-Feed URL Rewrite vulnerability zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewri… 2.10.3 osvpackagist
Description
Zend-Feed URL Rewrite vulnerability zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism. When these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content.
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
7.5 (HIGH)
HIGH · 75/100
2.10.3
2024-06-07
2024-12-04
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 8.4
EPSS: 36%
Published: 2024-11-05
CVE-2024-51736
exact
composer:
symfony/process
3.4.4 direct
defined in: drupal/drupal
CWE-77
Command Injection
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. 4.0.0 nvdosvpackagist
Description
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking. This issue has been addressed in release versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Weaknesses (CWE) (1)
  • CWE-77 — Command Injection
Metadata
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
8.4 (HIGH)
HIGH · 74.5/100
0.4% prob · 36th pct
4.0.0
2024-11-05
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 7.3
EPSS: 70%
Published: 2025-11-12
CVE-2025-64500
exact
composer:
symfony/http-foundation
3.4.4 direct
defined in: drupal/drupal
CWE-647 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. 4.0.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.
Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.3 (HIGH)
HIGH · 72.3/100
1.3% prob · 70th pct
4.0.0
2025-11-12
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (6)
  • cpe:2.3:a:sensiolabs:httpfoundation:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:httpfoundation:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:httpfoundation:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
MEDIUM 6.5
EPSS: 99%
Published: 2018-08-01
CVE-2018-14773
exact
composer:
symfony/http-foundation
3.4.4 direct
defined in: drupal/drupal
— An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. 3.4.14 nvdosvpackagist
Description
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets users override the path in the request URL via the X-Original-URL or X-Rewrite-URL HTTP request header. These headers are designed for IIS support, but it's not verified that the server is in fact running IIS, which means anybody who can send these requests to an application can trigger this. This affects \Symfony\Component\HttpFoundation\Request::prepareRequestUri() where X-Original-URL and X_REWRITE_URL are both used. The fix drops support for these methods so that they cannot be used as attack vectors such as web cache poisoning.
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
6.5 (MEDIUM)
HIGH · 71.8/100
58.1% prob · 99th pct
3.4.14
2018-08-01
2024-02-16
exact
nvd+osv+packagist
Affected CPE configurations (9)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
HIGH 7.1
EPSS: 45%
Published: 2026-05-20
CVE-2026-46627
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-400
Uncontrolled Resource Consumption (DoS)
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustio… 2.0.0 nvdpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.
Weaknesses (CWE) (1)
  • CWE-400 — Uncontrolled Resource Consumption (DoS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.1 (HIGH)
MEDIUM · 65.7/100
0.5% prob · 45th pct
2.0.0
2026-05-20
2026-07-16
exact
nvd+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.9
EPSS: 90%
Published: 2023-02-01
CVE-2022-24894
exact
composer:
symfony/http-kernel
3.4.4 direct
defined in: drupal/drupal
CWE-285
Improper Authorization
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. 4.0.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a recent change in the `AbstractSessionListener`, the response might contain a `Set-Cookie` header. If the Symfony HTTP cache system is enabled, this response might bill stored and return to the next clients. An attacker can use this vulnerability to retrieve the victim's session. This issue has been patched and is available for branch 4.4.
Weaknesses (CWE) (1)
  • CWE-285 — Improper Authorization
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L
5.9 (MEDIUM)
MEDIUM · 65.2/100
4.0% prob · 90th pct
4.0.0
2023-02-01
2025-02-13
exact
nvd+osv+packagist
Affected CPE configurations (5)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 7.1
EPSS: 36%
Published: 2026-05-27
CVE-2026-48806
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-693
Protection Mechanism Failure
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxE… 2.0.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0.
Weaknesses (CWE) (2)
  • CWE-693 — Protection Mechanism Failure
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.1 (MEDIUM)
MEDIUM · 64/100
0.4% prob · 36th pct
2.0.0
2026-05-27
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
HIGH 7.1
EPSS: 34%
Published: 2026-05-20
CVE-2026-47732
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invo… 2.0.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.1 (HIGH)
MEDIUM · 63.6/100
0.4% prob · 34th pct
2.0.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 7.1
EPSS: 31%
Published: 2026-05-27
CVE-2026-48807
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-693
Protection Mechanism Failure
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringab… 2.0.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.
Weaknesses (CWE) (2)
  • CWE-693 — Protection Mechanism Failure
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.1 (MEDIUM)
MEDIUM · 62.9/100
0.4% prob · 31th pct
2.0.0
2026-05-27
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.9
EPSS: 75%
Published: 2018-05-25
CVE-2018-11386
exact
composer:
symfony/http-foundation
3.4.4 direct
defined in: drupal/drupal
CWE-613
Insufficient Session Expiration
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. 3.4.11 nvdosvpackagist
Description
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources.
Weaknesses (CWE) (1)
  • CWE-613 — Insufficient Session Expiration
Metadata
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
5.9 (MEDIUM)
MEDIUM · 62.2/100
1.6% prob · 75th pct
3.4.11
2018-05-25
2024-02-17
exact
nvd+osv+packagist
Affected CPE configurations (6)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
HIGH 7.2
EPSS: 12%
Published: 2026-08-03
CVE-2026-69246
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-180 CWE-436
Interpretation Conflict
+2
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. 7.15.2 nvdosvpackagist
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable build, applying IDNA mapping, and uses the result to resolve, connect, name the TLS peer and address a proxy CONNECT, while the supplied Host suppresses the aligned one libcurl would have generated. For a URI host written as 127.0.0.%31, filter_var() rejects the host as an IP literal, yet libcurl decodes it to 127.0.0.1 and reaches loopback with no DNS lookup while the server receives Host: 127.0.0.%31. An attacker who influences a fetched URI can therefore reach a host the application's checks excluded and read whatever the host exposes of the response. The same divergence moves Guzzle's own decisions onto a spelling the transport does not use: no_proxy selects proxy routing from the literal host, and RedirectMiddleware decides from it whether to strip Authorization and Cookie. Exploitation requires the application to build a request URI from untrusted input and to make a host decision before handing it to Guzzle. This issue is fixed in versions 7.15.2 and 8.0.1.
Weaknesses (CWE) (4)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
7.2 (HIGH)
MEDIUM · 60/100
0.2% prob · 12th pct
7.15.2
2026-08-03
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 84%
Published: 2022-03-20
CVE-2022-24775
exact
composer:
guzzlehttp/psr7
1.4.2 direct
defined in: drupal/drupal
CWE-20
Improper Input Validation
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. 1.8.4 nvdosvpackagist
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.
Weaknesses (CWE) (1)
  • CWE-20 — Improper Input Validation
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
5.3 (MEDIUM)
MEDIUM · 59.2/100
2.5% prob · 84th pct
1.8.4
2022-03-20
2026-02-04
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 6.0
EPSS: 40%
Published: 2026-05-20
CVE-2026-46638
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-693
Protection Mechanism Failure
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, a… 2.0.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, and functions that should have been denied by SecurityPolicy::checkSecurity(). This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
  • CWE-693 — Protection Mechanism Failure
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.0 (MEDIUM)
MEDIUM · 56/100
0.5% prob · 40th pct
2.0.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 67%
Published: 2023-04-17
CVE-2023-29197
exact
composer:
guzzlehttp/psr7
1.4.2 direct
defined in: drupal/drupal
CWE-436
Interpretation Conflict
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. 1.9.1 nvdosvpackagist
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wild will also accept \n\n. This is a follow-up to CVE-2022-24775 where the fix was incomplete. The issue has been patched in versions 1.9.1 and 2.4.5. There are no known workarounds for this vulnerability. Users are advised to upgrade.
Weaknesses (CWE) (1)
  • CWE-436 — Interpretation Conflict
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
5.3 (MEDIUM)
MEDIUM · 55.9/100
1.2% prob · 67th pct
1.9.1
2023-04-17
2026-02-04
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 6.0
EPSS: 35%
Published: 2026-05-27
CVE-2026-48808
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-693
Protection Mechanism Failure
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are… 2.0.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0.
Weaknesses (CWE) (2)
  • CWE-693 — Protection Mechanism Failure
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.0 (MEDIUM)
MEDIUM · 54.9/100
0.4% prob · 35th pct
2.0.0
2026-05-27
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
HIGH 6.0
EPSS: 30%
Published: 2026-07-01
CVE-2026-49981
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-693
Protection Mechanism Failure
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allow… — nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.
Weaknesses (CWE) (2)
  • CWE-693 — Protection Mechanism Failure
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.0 (HIGH)
MEDIUM · 54/100
0.4% prob · 30th pct
2026-07-01
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 6.3
EPSS: 12%
Published: 2026-01-28
CVE-2026-24739
exact
composer:
symfony/process
3.4.4 direct
defined in: drupal/drupal
CWE-88
Argument Injection
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 5.4.51 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5, the Symfony Process component did not correctly treat some characters (notably `=`) as “special” when escaping arguments on Windows. When PHP is executed from an MSYS2-based environment (e.g. Git Bash) and Symfony Process spawns native Windows executables, MSYS2’s argument/path conversion can mis-handle unquoted arguments containing these characters. This can cause the spawned process to receive corrupted/truncated arguments compared to what Symfony intended. If an application (or tooling such as Composer scripts) uses Symfony Process to invoke file-management commands (e.g. `rmdir`, `del`, etc.) with a path argument containing `=`, the MSYS2 conversion layer may alter the argument at runtime. In affected setups this can result in operations being performed on an unintended path, up to and including deletion of the contents of a broader directory or drive. The issue is particularly relevant when untrusted input can influence process arguments (directly or indirectly, e.g. via repository paths, extracted archive paths, temporary directories, or user-controlled configuration). Versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5 contains a patch for the issue. Some workarounds are available. Avoid running PHP/one's own tooling from MSYS2-based shells on Windows; prefer cmd.exe or PowerShell for workflows that spawn native executables. Avoid passing paths containing `=` (and similar MSYS2-sensitive characters) to Symfony Process when operating under Git Bash/MSYS2. Where applicable, configure MSYS2 to disable or restrict argument conversion (e.g. via `MSYS2_ARG_CONV_EXCL`), understanding this may affect other tooling behavior.
Weaknesses (CWE) (1)
  • CWE-88 — Argument Injection
Metadata
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
6.3 (MEDIUM)
MEDIUM · 52.8/100
0.2% prob · 12th pct
5.4.51
2026-01-28
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (5)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 6.5
EPSS: 3%
Published: 2026-08-03
CVE-2026-69245
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-180 CWE-346
Origin Validation Error
+1
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, … 7.15.2 nvdosvpackagist
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two spellings a transport reads as an address keep subdomain scope. Hexadecimal and mixed-base forms such as 0x7f000001 and 0177.0.0.0x1 go unrecognized while libcurl 8.21.0 reads both as 127.0.0.1. A percent-escaped Domain keeps that scope on both branches because percent-decoding sits above numeric parsing, so 192.168.0.%31 and 127.0.0.1%2e are registered names in the URI grammar rather than address literals, and no numeric rule in any base classifies them, while libcurl decodes the host before resolving and reads them as 192.168.0.1 and 127.0.0.1. A cookie stored for Domain=0x7f000001 is placed in the Cookie header of a request to evil.0x7f000001, disclosing a session identifier or token to a host that is not that address, and a response from evil.0x7f000001 setting Domain=0x7f000001 is accepted into the jar and replayed to the address, so a server answering for the look-alike name can fix a session or set application state. Exploitation requires the application to enable cookie support, address an origin by one of these spellings, and contact a host whose name ends in that spelling. This issue is fixed in versions 7.15.2 and 8.0.1.
Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
6.5 (MEDIUM)
MEDIUM · 52.7/100
0.1% prob · 3th pct
7.15.2
2026-08-03
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
LOW 5.3
EPSS: 41%
Published: 2026-05-27
CVE-2026-48805
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-693
Protection Mechanism Failure
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such … 2.0.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arrow_in_sandbox() to bypass sandbox callable restrictions. This issue is fixed in version 3.27.0.
Weaknesses (CWE) (1)
  • CWE-693 — Protection Mechanism Failure
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (LOW)
MEDIUM · 50.6/100
0.5% prob · 41th pct
2.0.0
2026-05-27
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.9
EPSS: 17%
Published: 2026-07-20
CVE-2026-67354
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-201 guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. 7.15.1 nvdosvpackagist
Description
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redirect (e.g., HTTPS to HTTPS). An attacker who controls the redirect destination can read this fragment from the incoming Referer header, potentially disclosing one-time login secrets, access tokens, state values, or other sensitive client data to a server never meant to receive it. The referer setting is disabled by default. Fixed in 7.15.1, which strips the fragment before generating the Referer value.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.9 (MEDIUM)
MEDIUM · 50.6/100
0.3% prob · 17th pct
7.15.1
2026-07-20
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.9
EPSS: 14%
Published: 2026-07-20
CVE-2026-67355
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-201 guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. 7.15.1 nvdosvpackagist
Description
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.9 (MEDIUM)
MEDIUM · 50/100
0.2% prob · 14th pct
7.15.1
2026-07-20
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.8
EPSS: 12%
Published: 2026-06-18
CVE-2026-55767
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-346
Origin Validation Error
CWE-1286
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. 7.12.1 nvdosvpackagist
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string; SetCookie::validate() only rejected a strictly empty domain, so these cookies could be stored and the empty normalized domain was treated as matching any request host. An attacker-controlled origin that an application requests with a shared cookie jar can therefore set a cookie that Guzzle later sends to unrelated hosts using the same jar. This may allow cookie injection or session fixation against downstream services, depending on how those services interpret the injected cookie. This vulnerability is fixed in 7.12.1.
Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
5.8 (MEDIUM)
MEDIUM · 48.7/100
0.2% prob · 12th pct
7.12.1
2026-06-18
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.9
EPSS: 4%
Published: 2026-06-18
CVE-2026-55568
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-311
Missing Encryption of Sensitive Data
CWE-319
Cleartext Transmission of Sensitive Information
+1
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. 7.12.1 nvdosvpackagist
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or CURLOPT_PROXYUSERPWD) are sent without encryption, and the CONNECT target host and port for tunneled HTTPS requests are exposed. The built-in cURL handlers (GuzzleHttp\Handler\CurlHandler and GuzzleHttp\Handler\CurlMultiHandler, used by default whenever the PHP cURL extension is available) accept an https:// proxy. libcurl older than 7.50.2 silently treats an https:// proxy as a plaintext http:// proxy. The TLS connection to the proxy is never established, and the proxy leg is cleartext with no error or warning. An application is affected when it sends requests through one of the built-in cURL handlers, configures an https:// proxy expecting the proxy connection itself to be encrypted, and runs with libcurl older than 7.50.2. This vulnerability is fixed in 7.12.1.
Weaknesses (CWE) (3)
  • CWE-311 — Missing Encryption of Sensitive Data
  • CWE-319 — Cleartext Transmission of Sensitive Information
  • CWE-636 (unknown weakness)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
5.9 (MEDIUM)
MEDIUM · 48.1/100
0.1% prob · 4th pct
7.12.1
2026-06-18
2026-09-10
exact
nvd+osv+packagist
External links (1)
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
LOW 5.3
EPSS: 26%
Published: 2026-05-20
CVE-2026-46635
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAll… 2.0.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAllowed(), allowing an untrusted template author with column in allowedFilters to read properties that are not in the sandbox allowlist. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (LOW)
MEDIUM · 47.7/100
0.3% prob · 26th pct
2.0.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 4.7
Published: 2024-06-07
GHSA-fq4p-86hh-42v9
exact
composer:
zendframework/zend-diactoros
1.4.1 direct
defined in: drupal/drupal
— Zend-Diactoros URL Rewrite vulnerability zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL … 1.8.4 osvpackagist
Description
Zend-Diactoros URL Rewrite vulnerability zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism. When these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content.
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
4.7 (MEDIUM)
MEDIUM · 47/100
1.8.4
2024-06-07
2024-12-04
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.1
EPSS: 29%
Published: 2026-05-26
CVE-2026-48784
exact
composer:
symfony/routing
3.4.4 direct
defined in: drupal/drupal
CWE-172 CWE-601
URL Redirection to Untrusted Site (Open Redirect)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 4.0.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
Weaknesses (CWE) (2)
  • CWE-172 (unknown weakness)
  • CWE-601 — URL Redirection to Untrusted Site (Open Redirect)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.1 (MEDIUM)
MEDIUM · 46.5/100
0.3% prob · 29th pct
4.0.0
2026-05-26
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 16%
Published: 2026-07-20
CVE-2026-67353
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-770
Allocation of Resources Without Limits or Throttling
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. 7.15.1 nvdosvpackagist
Description
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.
Weaknesses (CWE) (1)
  • CWE-770 — Allocation of Resources Without Limits or Throttling
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (MEDIUM)
MEDIUM · 45.7/100
0.2% prob · 16th pct
7.15.1
2026-07-20
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
LOW 5.1
EPSS: 22%
Published: 2026-05-20
CVE-2026-46628
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-116
Improper Encoding or Escaping of Output
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. 2.0.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
  • CWE-116 — Improper Encoding or Escaping of Output
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.1 (LOW)
MEDIUM · 45.3/100
0.3% prob · 22th pct
2.0.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 14%
Published: 2026-07-20
CVE-2026-67339
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. 7.14.2 nvdosvpackagist
Description
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.
Weaknesses (CWE) (1)
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (MEDIUM)
MEDIUM · 45.3/100
0.2% prob · 14th pct
7.14.2
2026-07-20
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 10%
Published: 2026-05-25
CVE-2026-48998
exact
composer:
guzzlehttp/psr7
1.4.2 direct
defined in: drupal/drupal
CWE-20
Improper Input Validation
CWE-918
Server-Side Request Forgery (SSRF)
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. 2.10.2 nvdosvpackagist
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. An attacker can provide a malformed Host header containing URI authority delimiters, such as `trusted.example@evil.example`. When the Host value is used to construct a URI, the malformed value can be reinterpreted as URI userinfo and host. This can cause the PSR-7 request URI host to differ from the original Host header value. Applications are affected if they parse attacker-controlled raw HTTP requests with `GuzzleHttp\Psr7\Message::parseRequest()` or the legacy 1.x `GuzzleHttp\Psr7\parse_request()` function, or if they build server requests from attacker-controlled server variables, then rely on the resulting URI host for routing, allow-list checks, or forwarding decisions. In affected forwarding or gateway scenarios, this may cause requests or credentials to be sent to an unintended host. The issue is patched in `2.10.2`. `1.x` is end-of-life and will not receive a patch. Some workarounds are available. Validate the `Host` header as `uri-host [ ":" port ]` before calling `Message::parseRequest()` or legacy `parse_request()` on untrusted HTTP request data, or before deriving routing and forwarding decisions from a parsed request URI. Reject Host values containing userinfo, path, query, or fragment delimiters.
Weaknesses (CWE) (2)
  • CWE-20 — Improper Input Validation
  • CWE-918 — Server-Side Request Forgery (SSRF)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3 (MEDIUM)
MEDIUM · 44.4/100
0.2% prob · 10th pct
2.10.2
2026-05-25
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 9%
Published: 2026-05-25
CVE-2026-49214
exact
composer:
guzzlehttp/psr7
1.4.2 direct
defined in: drupal/drupal
CWE-20
Improper Input Validation
CWE-93
CRLF Injection
+1
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. 2.10.2 nvdosvpackagist
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 `Uri` or `Request`. Third, the host component contains CRLF or another header-unsafe character. Fourth, the host is copied into the PSR-7 `Host` header when no explicit `Host` header is provided. Finally, the request is serialized or sent by an HTTP client that does not independently reject the malformed host. In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing `"\r\nX-Injected: yes"` can cause the generated `Host` header to span multiple HTTP header lines. Applications are affected when they use user-controlled URLs for outbound HTTP requests, URL forwarding, proxying, crawling, webhook delivery, or similar request-dispatch flows. In deployments involving HTTP/1.1 connection reuse, proxies, gateways, or load balancers, this malformed request may also contribute to request smuggling or cache poisoning, depending on how downstream components parse the request. The issue is patched in `2.10.2` and later. `1.x` is end-of-life and will not receive a patch. As a workaround, validate and reject all untrusted URI strings before constructing PSR-7 `Uri` or `Request` instances. Reject input containing ASCII control characters, whitespace, or DEL, including CRLF, tab, space, NUL, or DEL characters. Applications that forward requests should also ensure the final HTTP client or serializer rejects invalid URI and header data before writing requests to the network.
Weaknesses (CWE) (3)
  • CWE-20 — Improper Input Validation
  • CWE-93 — CRLF Injection
  • CWE-113 — HTTP Response Splitting
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
5.3 (MEDIUM)
MEDIUM · 44.2/100
0.2% prob · 9th pct
2.10.2
2026-05-25
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
LOW 3.7
EPSS: 71%
Published: 2019-03-12
CVE-2019-9942
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
— A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place. 1.38.0 nvdosvpackagist
Description
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
3.7 (LOW)
MEDIUM · 43.9/100
1.4% prob · 71th pct
1.38.0
2019-03-12
2024-02-16
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
MEDIUM 4.8
EPSS: 14%
Published: 2026-06-18
CVE-2026-55766
exact
composer:
guzzlehttp/psr7
1.4.2 direct
defined in: drupal/drupal
CWE-93
CRLF Injection
CWE-113
HTTP Response Splitting
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason… 2.12.1 nvdosvpackagist
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason phrase. If an application placed attacker-controlled data into one of those fields and later serialized the PSR-7 message as raw HTTP/1.x, for example with Message::toString() or an equivalent serializer, the serialized message could contain attacker-controlled header lines. The issue can also be reached through Message::parseRequest() or Message::parseResponse() when malformed raw messages are parsed into first-party PSR-7 objects and then serialized again. Creating or modifying a Request, Response, or other PSR-7 object alone is not sufficient. The issue requires the malformed message to be serialized and written to the network, forwarded, replayed, or otherwise processed by software that does not independently reject the malformed start line. This vulnerability is fixed in 2.12.1.
Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
4.8 (MEDIUM)
MEDIUM · 41.2/100
0.2% prob · 14th pct
2.12.1
2026-06-18
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
LOW
MEDIUM 4.7
EPSS: 6%
Published: 2026-07-20
CVE-2026-59883
exact
composer:
guzzlehttp/guzzle
6.3.0 direct
defined in: drupal/drupal
CWE-346
Origin Validation Error
CWE-384
Session Fixation
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matc… 7.12.3 nvdosvpackagist
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.
Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
4.7 (MEDIUM)
LOW · 38.9/100
0.2% prob · 6th pct
7.12.3
2026-07-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
LOW
MEDIUM 4.2
EPSS: 25%
Published: 2026-07-21
CVE-2026-59882
exact
composer:
guzzlehttp/psr7
1.4.2 direct
defined in: drupal/drupal
CWE-436
Interpretation Conflict
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::ge… 2.12.3 nvdosvpackagist
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.
Weaknesses (CWE) (1)
  • CWE-436 — Interpretation Conflict
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
4.2 (MEDIUM)
LOW · 38.6/100
0.3% prob · 25th pct
2.12.3
2026-07-21
2026-07-21
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
LOW
LOW 3.1
EPSS: 45%
Published: 2024-11-05
CVE-2024-50345
exact
composer:
symfony/http-foundation
3.4.4 direct
defined in: drupal/drupal
CWE-601
URL Redirection to Untrusted Site (Open Redirect)
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. 4.0.0 nvdosvpackagist
Description
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the `Request` class to redirect users to another domain. The `Request::create` methods now assert the URI does not contain invalid characters as defined by https://url.spec.whatwg.org/. This issue has been patched in versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Weaknesses (CWE) (1)
  • CWE-601 — URL Redirection to Untrusted Site (Open Redirect)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
3.1 (LOW)
LOW · 33.8/100
0.6% prob · 45th pct
4.0.0
2024-11-05
2025-11-03
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
LOW
LOW 3.1
EPSS: 39%
Published: 2024-08-30
CVE-2024-50343
exact
composer:
symfony/validator
3.4.4 direct
defined in: drupal/drupal
CWE-20
Improper Input Validation
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. 4.0.0 nvdosvpackagist
Description
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. Symfony as of versions 5.4.43, 6.4.11, and 7.1.4 now uses the `D` regex modifier to match the entire input. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Weaknesses (CWE) (1)
  • CWE-20 — Improper Input Validation
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
3.1 (LOW)
LOW · 32.6/100
0.5% prob · 39th pct
4.0.0
2024-08-30
2025-11-03
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
LOW
LOW 2.2
EPSS: 37%
Published: 2024-11-06
CVE-2024-51754
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-668
Exposure of Resource to Wrong Sphere
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments t… 2.0.0 nvdosvpackagist
Description
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments to a function or a filter for instance). This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue.
Weaknesses (CWE) (1)
  • CWE-668 — Exposure of Resource to Wrong Sphere
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
2.2 (LOW)
LOW · 25.1/100
0.4% prob · 37th pct
2.0.0
2024-11-06
2025-05-29
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
LOW
LOW 2.2
EPSS: 37%
Published: 2024-11-06
CVE-2024-51755
exact
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal
CWE-668
Exposure of Resource to Wrong Sphere
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. 2.0.0 nvdosvpackagist
Description
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the security check. This is a BC break. This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue.
Weaknesses (CWE) (1)
  • CWE-668 — Exposure of Resource to Wrong Sphere
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
2.2 (LOW)
LOW · 25/100
0.4% prob · 37th pct
2.0.0
2024-11-06
2024-11-12
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
LOW
MEDIUM 2.3
EPSS: 29%
Published: 2026-05-20
CVE-2026-45065
exact
composer:
symfony/routing
3.4.4 direct
defined in: drupal/drupal
CWE-185
Incorrect Regular Expression
CWE-601
URL Redirection to Untrusted Site (Open Redirect)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 4.0.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle alternatives match as unanchored substrings, allowing a value such as //evil.com to satisfy a common locale requirement and generate a protocol-relative off-site URL. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (2)
  • CWE-185 — Incorrect Regular Expression
  • CWE-601 — URL Redirection to Untrusted Site (Open Redirect)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2.3 (MEDIUM)
LOW · 24.1/100
0.3% prob · 29th pct
4.0.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock

laravel · bookstack (61)

framework laravel/framework 10.48.22 (42)

Direct (4)

Priority / severityAdvisory IDDependencyCWEDescriptionFix VersionSource
HIGH
HIGH 8.7
EPSS: 99%
Published: 2024-11-12
CVE-2024-52301
exact
composer:
laravel/framework
10.48.22 direct
defined in: bookstackapp/bookstack
CWE-88
Argument Injection
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the req… 10.48.23 nvdosvpackagist
Description
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs.
Weaknesses (CWE) (1)
  • CWE-88 — Argument Injection
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (HIGH)
HIGH · 89.3/100
44.8% prob · 99th pct
10.48.23
2024-11-12
2024-12-21
exact
nvd+osv+packagist
Affected CPE configurations (7)
  • cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
  • cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
  • cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
  • cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
  • cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
  • cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
HIGH
HIGH 8.9
EPSS: 51%
Published: 2026-05-19
CVE-2026-48019
exact
composer:
laravel/framework
10.48.22 direct
defined in: bookstackapp/bookstack
CWE-93
CRLF Injection
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may all… 11.0.0 nvdosvpackagist
Description
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in applications that send mail to user-supplied addresses. This issue has been patched in versions 12.60.0 and 13.10.0.
Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
8.9 (HIGH)
HIGH · 81.4/100
0.7% prob · 51th pct
11.0.0
2026-05-19
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.9
EPSS: 53%
Published: 2025-03-05
CVE-2025-27515
exact
composer:
laravel/framework
10.48.22 direct
defined in: bookstackapp/bookstack
CWE-155 Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. 10.48.29 nvdosvpackagist
Description
Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.9 (MEDIUM)
MEDIUM · 65.8/100
0.7% prob · 53th pct
10.48.29
2025-03-05
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (2)
  • cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
  • cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 4.2
Published: 2026-06-17
GHSA-crmm-hgp2-wgrp
exact
composer:
laravel/framework
10.48.22 direct
defined in: bookstackapp/bookstack
— Laravel Framework: Temporary Signed URL Path Confusion A vulnerability in Laravel's local filesystem driver allows temporary signed URLs to be parsed ambiguously, potentially misrouting requests and bypassing expiration enforcement. Under… 12.61.1 osvpackagist
Description
Laravel Framework: Temporary Signed URL Path Confusion A vulnerability in Laravel's local filesystem driver allows temporary signed URLs to be parsed ambiguously, potentially misrouting requests and bypassing expiration enforcement. Under certain conditions, a generated temporary signed URL can be interpreted differently by the server than intended at signing time. This may cause requests to resolve to an unintended resource, and can prevent expiration from being enforced, allowing expired URLs to remain valid indefinitely. ### Impact - Expired temporary URLs may continue to be accepted - Requests may resolve to a different resource than the one that was signed - The upload variant may allow writes to reach an unintended destination
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
4.2 (MEDIUM)
MEDIUM · 42/100
12.61.1
2026-06-17
2026-09-10
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock

Indirect (38)

Priority / severityAdvisory IDDependencyCWEDescriptionFix VersionSource
CRITICAL
CRITICAL
Published: 2025-12-09
GHSA-5j8p-438x-rgg5
exact
composer:
onelogin/php-saml
4.2.0 direct
defined in: bookstackapp/bookstack
— SAML PHP Toolkit Vulnerability on xmlseclibs CVE-2025-66475 **Summary** There is a critical vulnerability on xmlseclibs [CVE-2025-66475](https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9), a dependency of p… 4.3.1 osvpackagist
Description
SAML PHP Toolkit Vulnerability on xmlseclibs CVE-2025-66475 **Summary** There is a critical vulnerability on xmlseclibs [CVE-2025-66475](https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9), a dependency of php-saml Update to the following versions of php-saml which forces the use of patched versions of xmlseclibs: - [2.21.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/2.21.1) - [3.8.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/3.8.1) - [4.3.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/4.3.1) **Impact** Signature Wrapping Vulnerabilities allows an attacker to impersonate a user.
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CRITICAL · 95/100
4.3.1
2025-12-09
2025-12-09
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
HIGH
CRITICAL 9.8
EPSS: 36%
Published: 2026-06-11
CVE-2026-54133
exact
composer:
mtdowling/jmespath.php
2.8.0 direct
defined in: bookstackapp/bookstack
CWE-20
Improper Input Validation
CWE-94
Code Injection
+1
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. 2.9.1 nvdosvpackagist
Description
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an attacker-controlled JMESPath expression. The compiler emits parsed JMESPath function names into generated PHP source without sufficient escaping. A crafted expression can cause the generated cache file to contain executable attacker-controlled PHP, which is then loaded by the compiler runtime. The issue is patched in `2.9.1` and later. As a workaround, disable `JP_PHP_COMPILE` and do not use `JmesPath\CompilerRuntime` with attacker-controlled expressions. Use the default `AstRuntime` for untrusted expressions. Applications that must continue accepting untrusted JMESPath expressions before upgrading should ensure those expressions are never evaluated by the compiler runtime.
Weaknesses (CWE) (3)
  • CWE-20 — Improper Input Validation
  • CWE-94 — Code Injection
  • CWE-116 — Improper Encoding or Escaping of Output
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 (CRITICAL)
HIGH · 85.5/100
0.4% prob · 36th pct
2.9.1
2026-06-11
2026-08-18
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:jmespath:jmespath:*:*:*:*:*:php:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
HIGH
HIGH
Published: 2026-03-27
GHSA-27qh-8cxx-2cr5
exact
composer:
aws/aws-sdk-php
3.322.6 direct
defined in: bookstackapp/bookstack
— AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters ### Summary This notification is related to the [CloudFront signing utilities](https://github.com/aws/aws-sdk-php/blob/master/src/CloudFront/Signer.php) in th… — osvpackagist
Description
AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters ### Summary This notification is related to the [CloudFront signing utilities](https://github.com/aws/aws-sdk-php/blob/master/src/CloudFront/Signer.php) in the AWS SDK for PHP, which are used to generate Amazon CloudFront signed URLs and signed cookies. A defense-in-depth enhancement has been implemented to improve handling of special characters, such as double quotes and backslashes, in input values. ### Impact The CloudFront signing utilities build policy documents that define access restrictions for signed URLs and cookies. If an application passes unsanitized input containing special characters to these utilities, the resulting policy document may not reflect the application's intended access restrictions. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Applications that already follow AWS security best practices for input validation are not impacted. ### Impacted versions: 3.11.7 - 3.371.3 ### Patches On 3/3/2026, an enhancement was made to the AWS SDK for PHP version 3.371.4. The enhancement ensures that special characters in input values are correctly handled. It is recommended to upgrade to the latest version. ### Workarounds No workarounds are needed, but customers should ensure that the application is following security best practices: - Implement proper input validation in application code before passing values to CloudFront signing utilities - Update to the latest AWS SDK release on a regular basis - Follow AWS security best practices for SDK configuration ### References For any questions or comments about this advisory, it is recommended to contact AWS Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.co…
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N
HIGH · 75/100
2026-03-27
2026-09-10
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
HIGH
HIGH 7.5
Published: 2026-08-06
GHSA-g2gp-3wwq-f4ph
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
— league/commonmark: Denial of service via adjacent inline attribute blocks ### Impact With the Attributes extension enabled, `AttributesListener::findTargetAndDirection()` resolves each attribute node's target by walking outward through it… 2.9.0 osvpackagist
Description
league/commonmark: Denial of service via adjacent inline attribute blocks ### Impact With the Attributes extension enabled, `AttributesListener::findTargetAndDirection()` resolves each attribute node's target by walking outward through its siblings. For a run of N adjacent inline attribute blocks placed at the start of a block (with nothing to their left), each node scans the **entire** sibling list to the far-right end before giving up and falling back to the parent. Each resolution is therefore Θ(N) and the whole run is **Θ(N²)**. Reaching the path requires `AttributesExtension` (opt-in, but first-party: `League\CommonMark\Extension\Attributes\AttributesExtension`). No other configuration matters — the quadratic walk runs unconditionally during parsing and is **not** gated by the `attributes/allow` allow-list, the `on*` hardening added in 2.7.0, or `allow_unsafe_links`. An unauthenticated attacker can submit a **~32 KB** input (`{#a}` repeated 8,000 times) that takes **over 5 seconds** to convert, with time growing quadratically in input length — a cheap denial of service. Availability impact only. **The Attributes extension was introduced in 1.5.0 (May 2020) with this outward-walk resolver present from the first commit, so all releases from 1.5.0 onward (including every 2.x) are affected.** ### Workarounds There is no library-level configuration that gates the quadratic walk. Integrators who cannot upgrade can only reduce exposure indirectly: - **Disable the Attributes extension** for untrusted input, or - **Impose a strict maximum input length before conversion** — noting that because the cost is quadratic, even a modest cap must be small to meaningfully bound worst-case CPU. Upgrading to a release containing the fix is recommended.
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
HIGH · 75/100
2.9.0
2026-08-06
2026-08-06
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
HIGH
HIGH 7.5
Published: 2026-08-06
GHSA-jfm3-95jq-q3rf
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
— league/commonmark: Denial of service via duplicate footnote definitions ### Impact The Footnote extension records one backref per footnote *reference* and then appends the **entire** backref list for **every** footnote *definition* block… 2.9.0 osvpackagist
Description
league/commonmark: Denial of service via duplicate footnote definitions ### Impact The Footnote extension records one backref per footnote *reference* and then appends the **entire** backref list for **every** footnote *definition* block in the document, without ever de-duplicating or removing repeated definitions of the same label (`GatherFootnotesListener`, populated by `NumberFootnotesListener`). A document that references a single label N times and also supplies N duplicate `[^a]:` definitions of that label therefore produces **N × N** `FootnoteBackref` nodes, so output size, parse time, and peak memory are all **O(N²)**. Reaching the vulnerable path requires `FootnoteExtension` to be registered on the `Environment`. This is opt-in, but is a commonly enabled GFM-style feature; no other non-default configuration is required. An unauthenticated attacker can expand a **~10 KB** request into a **~62 MB** HTML response, **~3 s** of CPU, and **~440 MB** of peak memory — enough to OOM-kill a default 128 MB PHP worker and deny service. Availability impact only; no confidentiality or integrity effect. **The Footnote extension was introduced in 1.5.0 (May 2020) with this backref logic present from the first commit, so all releases from 1.5.0 onward (including every 2.x through 2.8.x) are affected.** ### Workarounds There is no library-level option to cap the number of footnotes, references, or definitions, so no configuration switch prevents the amplification. Integrators who cannot upgrade should: - **Disable the Footnote extension** for untrusted input, or - **Enforce a strict input-size limit before conversion** — but note this is a weak control here, since the ~10 KB payload that already triggers the 62 MB / ~440 MB blowup is well within typical request-body limits, so any cap must be aggressively small to help. Upgrading to the patched release is the recommended remediation.
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
HIGH · 75/100
2.9.0
2026-08-06
2026-08-06
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
HIGH
HIGH 7.5
Published: 2026-08-06
GHSA-mh25-x5hq-wrqp
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
— league/commonmark: Denial of service via colliding heading slugs ### Impact `UniqueSlugNormalizer::normalize()` makes each slug document-unique by searching for an unused numeric suffix, but **restarts that search from `1` on every collis… 2.9.0 osvpackagist
Description
league/commonmark: Denial of service via colliding heading slugs ### Impact `UniqueSlugNormalizer::normalize()` makes each slug document-unique by searching for an unused numeric suffix, but **restarts that search from `1` on every collision**. The k-th heading that collapses to the same base slug performs k−1 array lookups, so K colliding slugs cost Σ(k−1) = **O(K²)**. An attacker can force every heading onto a single base slug trivially — many empty ATX headings, identical heading text, or punctuation-only headings that normalize to the empty string. The path is reached whenever the shared slug normalizer runs over attacker-controlled text. That happens when `HeadingPermalinkExtension` is registered (its `HeadingPermalinkProcessor` normalizes every heading), independently through `FootnoteExtension` (its `AnonymousFootnoteRefParser` normalizes every `^[label]` reference), and on any `TableOfContentsExtension` site (which requires `HeadingPermalinkExtension` to be co-registered). The default `slug_normalizer/unique` setting (`UniqueSlugNormalizerInterface::PER_DOCUMENT`) accumulates collisions across the whole document. No authentication is required — a small document body turns into seconds of CPU and denies service. Availability impact only. **`UniqueSlugNormalizer` was introduced in 2.0.0 (first shipped in 2.0.0-beta1, May 2021); the 1.x heading-permalink slug generator performed no de-duplication and is not affected. All 2.x releases (including 2.8.x) are affected.** ### Workarounds Integrators who cannot upgrade immediately can: - **Set `slug_normalizer/unique` to `false` / `UniqueSlugNormalizerInterface::DISABLED`**, which stops the de-duplication scan entirely — at the cost of losing id uniqueness (colliding headings then share an anchor). - **Disable `HeadingPermalinkExtension`** (and `TableOfContentsExtension`, which depends on it), and `FootnoteExtension` where anonymous footnotes reach the same normalizer, for untrusted Markdown. - **Cap the accept…
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
HIGH · 75/100
2.9.0
2026-08-06
2026-08-06
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
HIGH
HIGH 8.4
EPSS: 36%
Published: 2024-11-05
CVE-2024-51736
exact
composer:
symfony/process
6.4.12 direct
defined in: bookstackapp/bookstack
CWE-77
Command Injection
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. 6.4.14 nvdosvpackagist
Description
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking. This issue has been addressed in release versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Weaknesses (CWE) (1)
  • CWE-77 — Command Injection
Metadata
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
8.4 (HIGH)
HIGH · 74.5/100
0.4% prob · 36th pct
6.4.14
2024-11-05
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
HIGH
HIGH 7.3
EPSS: 70%
Published: 2025-11-12
CVE-2025-64500
exact
composer:
symfony/http-foundation
6.4.12 direct
defined in: bookstackapp/bookstack
CWE-647 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. 6.4.29 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.
Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.3 (HIGH)
HIGH · 72.3/100
1.3% prob · 70th pct
6.4.29
2025-11-12
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (6)
  • cpe:2.3:a:sensiolabs:httpfoundation:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:httpfoundation:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:httpfoundation:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 8.2
EPSS: 5%
Published: 2026-03-13
CVE-2026-32313
exact
composer:
robrichards/xmlseclibs
3.1.1 direct
defined in: bookstackapp/bookstack
CWE-354
Improper Validation of Integrity Check Value
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. 3.1.5 nvdosvpackagist
Description
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover the GHASH key, and decrypt the encrypted nodes. It also allows to forge arbitrary ciphertexts without knowing the encryption key. This vulnerability is fixed in 3.1.5.
Weaknesses (CWE) (1)
  • CWE-354 — Improper Validation of Integrity Check Value
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
8.2 (HIGH)
MEDIUM · 66.6/100
0.2% prob · 5th pct
3.1.5
2026-03-13
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:xmlseclibs_project:xmlseclibs:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 7.5
EPSS: 28%
Published: 2026-08-06
CVE-2026-71488
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
CWE-407
Inefficient Algorithmic Complexity
CWE-1050
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths… 2.9.0 nvdosvpackagist
Description
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate the remaining line at every URL-like prefix, allowing an attacker who can submit Markdown for conversion to consume disproportionate CPU time with a comparatively small request. This issue is fixed in 2.9.0.
Weaknesses (CWE) (2)
  • CWE-407 — Inefficient Algorithmic Complexity
  • CWE-1050 (unknown weakness)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
MEDIUM · 65.6/100
0.3% prob · 28th pct
2.9.0
2026-08-06
2026-08-21
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.9
EPSS: 46%
Published: 2026-05-26
CVE-2026-48736
exact
composer:
symfony/http-foundation
6.4.12 direct
defined in: bookstackapp/bookstack
CWE-184
Incomplete List of Disallowed Inputs
CWE-918
Server-Side Request Forgery (SSRF)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 6.4.41 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
Weaknesses (CWE) (2)
  • CWE-184 — Incomplete List of Disallowed Inputs
  • CWE-918 — Server-Side Request Forgery (SSRF)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.9 (MEDIUM)
MEDIUM · 64.4/100
0.6% prob · 46th pct
6.4.41
2026-05-26
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 7.5
EPSS: 22%
Published: 2026-09-01
CVE-2026-86429
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
CWE-407
Inefficient Algorithmic Complexity
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. 2.9.1 nvdosvpackagist
Description
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can submit small, specially crafted Markdown documents — such as text alternating with unpaired quotes, contiguous runs of block-level attribute blocks, or repeated class attributes — to trigger disproportionate CPU consumption and cause a denial of service. Fixed in 2.9.1.
Weaknesses (CWE) (1)
  • CWE-407 — Inefficient Algorithmic Complexity
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.5 (HIGH)
MEDIUM · 64.4/100
0.3% prob · 22th pct
2.9.1
2026-09-01
2026-09-08
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 7.5
EPSS: 21%
Published: 2026-09-01
CVE-2026-86430
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
CWE-407
Inefficient Algorithmic Complexity
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. 2.9.1 nvdosvpackagist
Description
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing.
Weaknesses (CWE) (1)
  • CWE-407 — Inefficient Algorithmic Complexity
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.5 (HIGH)
MEDIUM · 64.2/100
0.3% prob · 21th pct
2.9.1
2026-09-01
2026-09-08
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 7.5
EPSS: 21%
Published: 2024-12-09
CVE-2024-58382
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
CWE-407
Inefficient Algorithmic Complexity
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. 2.6.0 nvdosvpackagist
Description
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs designed to trigger worst-case performance, and sending multiple requests in parallel exhausts CPU resources and PHP-FPM processes.
Weaknesses (CWE) (1)
  • CWE-407 — Inefficient Algorithmic Complexity
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.5 (HIGH)
MEDIUM · 64.1/100
0.3% prob · 21th pct
2.6.0
2024-12-09
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 7.5
EPSS: 21%
Published: 2026-09-01
CVE-2026-86428
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
CWE-407
Inefficient Algorithmic Complexity
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. 2.10.0 nvdosvpackagist
Description
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing.
Weaknesses (CWE) (1)
  • CWE-407 — Inefficient Algorithmic Complexity
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.5 (HIGH)
MEDIUM · 64.1/100
0.3% prob · 21th pct
2.10.0
2026-09-01
2026-09-08
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
LOW 6.9
EPSS: 44%
Published: 2026-05-26
CVE-2026-46644
exact
composer:
symfony/polyfill-intl-idn
1.31.0 direct
defined in: bookstackapp/bookstack
CWE-1289 Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. 1.38.1 nvdosvpackagist
Description
Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33 requirement that decoded ACE labels contain at least one non-ASCII code point. Originally unequal domain names can be regarded as equal, which can lead to blacklist bypassing, inconsistent URL parsing, and server-side request forgery in applications using the polyfill to canonicalise or compare hostnames. This issue is fixed in version 1.38.1.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.9 (LOW)
MEDIUM · 64/100
0.5% prob · 44th pct
1.38.1
2026-05-26
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.3
EPSS: 53%
Published: 2026-07-22
CVE-2026-59942
exact
composer:
dompdf/dompdf
3.0.0 direct
defined in: bookstackapp/bookstack
CWE-400
Uncontrolled Resource Consumption (DoS)
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. 3.1.6 nvdosvpackagist
Description
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An attacker can crash the PHP process by providing a specially crafted HTML document containing a single image with massive dimensions (e.g., 30,000x30,000 pixels). While Dompdf implements internal checks to validate image dimensions, these can be bypassed by using a high-entropy image (such as random noise) encoded in Base64 and wrapped in specific CSS containers. The vulnerability exists because the dimension validation happens early, but the resource allocation for calculating the object's bounding box and internal buffers during the rendering phase does not strictly limit the cumulative CPU time or memory usage for a single object that has passed the initial check. An unauthenticated remote attacker can cause a complete Denial of Service on the web server by submitting a crafted HTML string. This affects any application that allows users to provide HTML content or URLs that are subsequently converted to PDF using Dompdf. This issue has been fixed in version 3.16.
Weaknesses (CWE) (1)
  • CWE-400 — Uncontrolled Resource Consumption (DoS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (MEDIUM)
MEDIUM · 61.1/100
0.7% prob · 53th pct
3.1.6
2026-07-22
2026-07-22
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:dompdf_project:dompdf:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 7.5
EPSS: 5%
Published: 2026-05-21
CVE-2026-46643
exact
composer:
knplabs/knp-snappy
1.5.0 direct
defined in: bookstackapp/bookstack
CWE-78
OS Command Injection
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. — nvdpackagist
Description
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1, on POSIX, escapeshellarg(‘/usr/bin/wkhtmltopdf’) returns the literal string ‘/usr/bin/wkhtmltopdf’ with the single-quote characters included. is_executable() then looks for a file whose actual name contains those quote characters, which essentially never exists. The safe branch is dead code and $command always falls through to the raw, unescaped value. The rest of the arguments (options, input, output) are escaped correctly, so injection has to land in the binary string itself. That happens whenever the binary path is sourced from configuration that is user-influenced, derived from environment variables that ultimately come from request data, or concatenated with any user-controlled fragment. This issue has been patched in version 1.7.1.
Weaknesses (CWE) (1)
  • CWE-78 — OS Command Injection
Metadata
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.5 (HIGH)
MEDIUM · 61/100
0.2% prob · 5th pct
2026-05-21
2026-06-17
exact
nvd+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.3
EPSS: 53%
Published: 2025-01-08
CVE-2025-22145
exact
composer:
nesbot/carbon
2.72.5 direct
defined in: bookstackapp/bookstack
CWE-98 Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload files with .php extension in an folder t… 2.72.6 nvdosvpackagist
Description
Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload files with .php extension in an folder that allows include or require to read it, then they are at risk of arbitrary code ran on their servers. This vulnerability is fixed in 3.8.4 and 2.72.6.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (MEDIUM)
MEDIUM · 60.9/100
0.7% prob · 53th pct
2.72.6
2025-01-08
2025-02-25
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 6.3
EPSS: 47%
Published: 2026-05-20
CVE-2026-45067
exact
composer:
symfony/mime
6.4.12 direct
defined in: bookstackapp/bookstack
CWE-93
CRLF Injection
### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers… 6.4.40 nvdosvpackagist
Description
### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers treat it as a security boundary. The constructor accepts email addresses whose local-part (the part before `@`) is an RFC-5322 *quoted string* containing raw `\r\n` bytes — e.g. `"x\r\nBcc: attacker@evil"@example.com`. The stored address is later emitted verbatim into (1) the rendered message headers and (2) `SmtpTransport`'s `MAIL FROM:<...>` / `RCPT TO:<...>` protocol lines, turning the embedded CRLF into a new mail header and/or a new SMTP command. ### Resolution The `Address` constructor now rejects addresses containing line breaks. The patch for this issue is available [here](https://github.com/symfony/symfony/commit/dc2dbd29211eb4ddc451373fa1374fb926e94604) for branch 5.4. ### Credits We would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (HIGH)
MEDIUM · 59.9/100
0.6% prob · 47th pct
6.4.40
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.3
EPSS: 43%
Published: 2026-07-22
CVE-2026-59941
exact
composer:
dompdf/dompdf
3.0.0 direct
defined in: bookstackapp/bookstack
CWE-400
Uncontrolled Resource Consumption (DoS)
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bounds width × height before the image is converted through GD.… 3.1.6 nvdosvpackagist
Description
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bounds width × height before the image is converted through GD. A 58-byte BMP whose header declares e.g. 6000×6000 is accepted and later drives imagecreatetruecolor($width, $height) (and PHP's native BMP decoder) to allocate the full pixel canvas. A payload can fit in a single HTTP request: the BMP can be inlined as a data:image/bmp;base64,… URI inside attacker-controlled HTML, so no upload, no remote fetch, and no chroot-reachable file is required. I measured a 169-byte request driving a dompdf render to ~412 MB peak RSS and ~4.8 s of CPU/wall time, versus ~34 MB for an identically-sized benign request — roughly a 12× memory amplification per request, repeatable and unauthenticated. This issue has been fixed in version 3.16.
Weaknesses (CWE) (1)
  • CWE-400 — Uncontrolled Resource Consumption (DoS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (MEDIUM)
MEDIUM · 58.9/100
0.5% prob · 43th pct
3.1.6
2026-07-22
2026-07-22
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:dompdf_project:dompdf:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.9
EPSS: 17%
Published: 2026-05-21
CVE-2026-46683
exact
composer:
knplabs/knp-snappy
1.5.0 direct
defined in: bookstackapp/bookstack
CWE-918
Server-Side Request Forgery (SSRF)
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local file read vulnerability via the xsl-style-sheet option. — nvdosvpackagist
Description
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local file read vulnerability via the xsl-style-sheet option. This issue has been patched in version 1.7.0.
Weaknesses (CWE) (1)
  • CWE-918 — Server-Side Request Forgery (SSRF)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.9 (MEDIUM)
MEDIUM · 58.5/100
0.2% prob · 17th pct
2026-05-21
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.4
EPSS: 30%
Published: 2025-05-05
CVE-2025-46734
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
CWE-79
Cross-site Scripting (XSS)
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls … 2.7.0 nvdosvpackagist
Description
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls into HTML. The league/commonmark library provides configuration options such as `html_input: 'strip'` and `allow_unsafe_links: false` to mitigate cross-site scripting (XSS) attacks by stripping raw HTML and disallowing unsafe links. However, when the Attributes Extension is enabled, it introduces a way for users to inject arbitrary HTML attributes into elements via Markdown syntax using curly braces. Version 2.7.0 contains three changes to prevent this XSS attack vector: All attributes starting with `on` are considered unsafe and blocked by default; support for an explicit allowlist of allowed HTML attributes; and manually-added `href` and `src` attributes now respect the existing `allow_unsafe_links` configuration option. If upgrading is not feasible, please consider disabling the `AttributesExtension` for untrusted users and/or filtering the rendered HTML through a library like HTMLPurifier.
Weaknesses (CWE) (1)
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
6.4 (MEDIUM)
MEDIUM · 57.2/100
0.4% prob · 30th pct
2.7.0
2025-05-05
2026-03-20
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.3
EPSS: 33%
Published: 2026-05-20
CVE-2026-45070
exact
composer:
symfony/mime
6.4.12 direct
defined in: bookstackapp/bookstack
CWE-93
CRLF Injection
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 6.4.40 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (MEDIUM)
MEDIUM · 57/100
0.4% prob · 33th pct
6.4.40
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.3
EPSS: 26%
Published: 2026-07-22
CVE-2026-56722
exact
composer:
dompdf/dompdf
3.0.0 direct
defined in: bookstackapp/bookstack
CWE-20
Improper Input Validation
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a  data:  URI, because dompdf… 3.1.6 nvdosvpackagist
Description
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a  data:  URI, because dompdf processes the SVG twice and the second pass does not enforce the same protections as the first. When rendering, dompdf hands the SVG to the separate  php-svg-lib  library with external references forced on, and that library has no knowledge of the chroot directory, blocks only the  phar://  scheme, and ultimately reads the referenced file with no path or protocol validation. This lets an external, unauthenticated attacker read arbitrary image files from the server's file system in the default configuration. This issue has been fixed in version 3.16.
Weaknesses (CWE) (1)
  • CWE-20 — Improper Input Validation
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (MEDIUM)
MEDIUM · 55.7/100
0.3% prob · 26th pct
3.1.6
2026-07-22
2026-07-22
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:dompdf_project:dompdf:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.3
EPSS: 23%
Published: 2026-07-22
CVE-2026-59943
exact
composer:
dompdf/dompdf
3.0.0 direct
defined in: bookstackapp/bookstack
CWE-209
Generation of Error Message Containing Sensitive Information
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when render… 3.1.6 nvdosvpackagist
Description
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when rendering PDF files using image references within a data-URI encoded SVG document. Using an <image> element inside a data-URI embedded SVG, an attacker can attempt to embed other files via the href or xlink:href attributes. When processing a file that does not exist (e.g. file:///DOESNOTEXIST), dompdf behaves differently than it does when accessing a file or directory that actually exists on the filesystem. This issue has been fixed in version 3.16.
Weaknesses (CWE) (1)
  • CWE-209 — Generation of Error Message Containing Sensitive Information
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (MEDIUM)
MEDIUM · 55/100
0.3% prob · 23th pct
3.1.6
2026-07-22
2026-07-22
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:dompdf_project:dompdf:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.3
EPSS: 16%
Published: 2026-03-19
CVE-2026-33347
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
CWE-79
Cross-site Scripting (XSS)
CWE-185
Incorrect Regular Expression
+1
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matchi… — nvdosvpackagist
Description
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.
Weaknesses (CWE) (3)
  • CWE-79 — Cross-site Scripting (XSS)
  • CWE-185 — Incorrect Regular Expression
  • CWE-918 — Server-Side Request Forgery (SSRF)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (MEDIUM)
MEDIUM · 53.5/100
0.2% prob · 16th pct
2026-03-19
2026-03-27
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.3
Published: 2026-08-06
GHSA-mj63-m3rc-8ppr
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
— league/commonmark: Denial of service via deeply nested XML output ### Impact `XmlRenderer` pretty-prints XML by emitting depth-proportional indentation whitespace for **every** opening and closing tag. 2.9.0 osvpackagist
Description
league/commonmark: Denial of service via deeply nested XML output ### Impact `XmlRenderer` pretty-prints XML by emitting depth-proportional indentation whitespace for **every** opening and closing tag. For a tree of depth n, the indentation alone sums to **O(n²)** bytes of output (and corresponding memory), reachable through `MarkdownToXmlConverter` — e.g. `str_repeat('> ', $depth) . "x\n"`, a single line of nested blockquotes — or through a direct `XmlRenderer::renderDocument()` call on an attacker-influenced AST. This affects applications that convert untrusted Markdown to XML, which is an **opt-in** output path. The parser's `max_nesting_level` bounds the depth of *parser-created* trees, but its default is high enough to reach damaging sizes, can be raised by the host application, and does not constrain custom or programmatically built ASTs handed straight to the renderer. The result is a memory / output-size amplification rather than a hard crash, which is why this issue is rated **Medium** rather than High. No confidentiality or integrity impact. XML rendering was introduced in 2.0.0 (first shipped in 2.0.0-beta1, June 2021) and has emitted depth-proportional indentation ever since, so all 2.x releases are affected (verified against 2.8.x, clean upstream `1902f60f`). 1.x has no XML renderer and is not affected. ### Workarounds Applications converting untrusted Markdown to XML should: - **Lower `max_nesting_level`** to a conservative value appropriate to expected content, so the parser refuses to build extremely deep trees. This is the most direct lever for parser-produced ASTs, but does not protect trees built programmatically and passed straight to `XmlRenderer`. - **Cap input size before conversion**, since the amplification is driven by input-proportional depth. - **Constrain XML consumers** with memory / output-size limits (and streaming or size caps on any downstream XML parser or storage) so one request cannot allocate unbounded output. - **Prefer H…
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
5.3 (MEDIUM)
MEDIUM · 53/100
2.9.0
2026-08-06
2026-08-06
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.3
EPSS: 12%
Published: 2026-01-28
CVE-2026-24739
exact
composer:
symfony/process
6.4.12 direct
defined in: bookstackapp/bookstack
CWE-88
Argument Injection
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 6.4.33 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5, the Symfony Process component did not correctly treat some characters (notably `=`) as “special” when escaping arguments on Windows. When PHP is executed from an MSYS2-based environment (e.g. Git Bash) and Symfony Process spawns native Windows executables, MSYS2’s argument/path conversion can mis-handle unquoted arguments containing these characters. This can cause the spawned process to receive corrupted/truncated arguments compared to what Symfony intended. If an application (or tooling such as Composer scripts) uses Symfony Process to invoke file-management commands (e.g. `rmdir`, `del`, etc.) with a path argument containing `=`, the MSYS2 conversion layer may alter the argument at runtime. In affected setups this can result in operations being performed on an unintended path, up to and including deletion of the contents of a broader directory or drive. The issue is particularly relevant when untrusted input can influence process arguments (directly or indirectly, e.g. via repository paths, extracted archive paths, temporary directories, or user-controlled configuration). Versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5 contains a patch for the issue. Some workarounds are available. Avoid running PHP/one's own tooling from MSYS2-based shells on Windows; prefer cmd.exe or PowerShell for workflows that spawn native executables. Avoid passing paths containing `=` (and similar MSYS2-sensitive characters) to Symfony Process when operating under Git Bash/MSYS2. Where applicable, configure MSYS2 to disable or restrict argument conversion (e.g. via `MSYS2_ARG_CONV_EXCL`), understanding this may affect other tooling behavior.
Weaknesses (CWE) (1)
  • CWE-88 — Argument Injection
Metadata
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
6.3 (MEDIUM)
MEDIUM · 52.8/100
0.2% prob · 12th pct
6.4.33
2026-01-28
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (5)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.1
EPSS: 16%
Published: 2026-08-06
CVE-2026-71478
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
CWE-79
Cross-site Scripting (XSS)
CWE-86 +1
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, … — nvdosvpackagist
Description
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0.
Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 (MEDIUM)
MEDIUM · 52/100
0.2% prob · 16th pct
2026-08-06
2026-08-21
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.0
EPSS: 16%
Published: 2025-12-08
CVE-2025-66578
exact
composer:
robrichards/xmlseclibs
3.1.1 direct
defined in: bookstackapp/bookstack
CWE-248
Uncaught Exception
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authentication bypass vulnerability due to a flaw in the libxml2 canonicalization process during document transformation. — nvdosvpackagist
Description
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authentication bypass vulnerability due to a flaw in the libxml2 canonicalization process during document transformation. When libxml2’s canonicalization is invoked on an invalid XML input, it may return an empty string rather than a canonicalized node. xmlseclibs then proceeds to compute the DigestValue over this empty string, treating it as if canonicalization succeeded. This issue is fixed in version 3.1.4. Workarounds include treating canonicalization failures (exceptions or nil/empty outputs) as fatal and aborting validation, and/or adding explicit checks to reject when canonicalize returns nil/empty or raises errors.
Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
6.0 (MEDIUM)
MEDIUM · 51.1/100
0.2% prob · 16th pct
2025-12-08
2025-12-09
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:xmlseclibs_project:xmlseclibs:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.1
EPSS: 29%
Published: 2026-05-26
CVE-2026-48784
exact
composer:
symfony/routing
6.4.12 direct
defined in: bookstackapp/bookstack
CWE-172 CWE-601
URL Redirection to Untrusted Site (Open Redirect)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 6.4.41 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
Weaknesses (CWE) (2)
  • CWE-172 (unknown weakness)
  • CWE-601 — URL Redirection to Untrusted Site (Open Redirect)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.1 (MEDIUM)
MEDIUM · 46.5/100
0.3% prob · 29th pct
6.4.41
2026-05-26
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 12%
Published: 2025-12-17
CVE-2025-14761
exact
composer:
aws/aws-sdk-php
3.322.6 direct
defined in: bookstackapp/bookstack
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Missing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" inste… 3.368.0 nvdosvpackagist
Description
Missing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade AWS SDK for PHP to version 3.368.0 or later
Weaknesses (CWE) (1)
  • CWE-327 — Use of a Broken or Risky Cryptographic Algorithm
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (MEDIUM)
MEDIUM · 44.7/100
0.2% prob · 12th pct
3.368.0
2025-12-17
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.1
EPSS: 12%
Published: 2026-03-06
CVE-2026-30838
exact
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack
CWE-79
Cross-site Scripting (XSS)
league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. — nvdosvpackagist
Description
league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. For example, <script\n> would pass through unfiltered and be rendered as a valid HTML tag by browsers. This is a cross-site scripting (XSS) vector for any application that relies on this extension to sanitize untrusted user input. All applications using the DisallowedRawHtml extension to process untrusted markdown are affected. Applications that use a dedicated HTML sanitizer (such as HTML Purifier) on the rendered output are not affected. This issue has been patched in version 2.8.1.
Weaknesses (CWE) (1)
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.1 (MEDIUM)
MEDIUM · 43.3/100
0.2% prob · 12th pct
2026-03-06
2026-03-20
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
LOW
LOW 3.1
EPSS: 45%
Published: 2024-11-05
CVE-2024-50345
exact
composer:
symfony/http-foundation
6.4.12 direct
defined in: bookstackapp/bookstack
CWE-601
URL Redirection to Untrusted Site (Open Redirect)
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. 6.4.14 nvdosvpackagist
Description
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the `Request` class to redirect users to another domain. The `Request::create` methods now assert the URI does not contain invalid characters as defined by https://url.spec.whatwg.org/. This issue has been patched in versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Weaknesses (CWE) (1)
  • CWE-601 — URL Redirection to Untrusted Site (Open Redirect)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
3.1 (LOW)
LOW · 33.8/100
0.6% prob · 45th pct
6.4.14
2024-11-05
2025-11-03
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
LOW
LOW 2.3
EPSS: 29%
Published: 2026-07-22
CVE-2026-55555
exact
composer:
dompdf/dompdf
3.0.0 direct
defined in: bookstackapp/bookstack
CWE-203
Observable Discrepancy
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. 3.1.6 nvdosvpackagist
Description
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. By providing malicious HTML that references local files via the file:// protocol repeatedly, an attacker can trigger PHP memory exhaustion. Because Dompdf behaves differently depending on whether a referenced local file exists (an existing file is processed repeatedly until it triggers an "Allowed memory size exhausted" crash, whereas a missing file fails fast or is ignored and never hits the memory limit), an attacker can use this observable discrepancy as an oracle to enumerate sensitive files on the server regardless of CHROOT restrictions. Exploitation requires the attacker to supply unrestricted or unsanitized HTML in a request that permits large data, plus a configuration where Dompdf's memory limit is low enough to be exhausted (with  $_dompdf_show_warnings=true  making the overflow easier to reach). This issue has been fixed in version 3.16.
Weaknesses (CWE) (1)
  • CWE-203 — Observable Discrepancy
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2.3 (LOW)
LOW · 24.2/100
0.4% prob · 29th pct
3.1.6
2026-07-22
2026-07-22
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:dompdf_project:dompdf:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
LOW
MEDIUM 2.3
EPSS: 29%
Published: 2026-05-20
CVE-2026-45065
exact
composer:
symfony/routing
6.4.12 direct
defined in: bookstackapp/bookstack
CWE-185
Incorrect Regular Expression
CWE-601
URL Redirection to Untrusted Site (Open Redirect)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 6.4.40 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle alternatives match as unanchored substrings, allowing a value such as //evil.com to satisfy a common locale requirement and generate a protocol-relative off-site URL. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (2)
  • CWE-185 — Incorrect Regular Expression
  • CWE-601 — URL Redirection to Untrusted Site (Open Redirect)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2.3 (MEDIUM)
LOW · 24.1/100
0.3% prob · 29th pct
6.4.40
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
LOW
LOW 2.3
EPSS: 26%
Published: 2026-07-22
CVE-2026-55554
exact
composer:
dompdf/dompdf
3.0.0 direct
defined in: bookstackapp/bookstack
CWE-20
Improper Input Validation
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with  realpath() . 3.1.6 nvdosvpackagist
Description
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with  realpath() . Because normalization strips the trailing directory separator from  $chrootPath , the check only verifies that  $chrootPath  is a string prefix of $realfile, so a chroot of  /var/www  also matches sibling directories like /var/www2 , /var/www-admin, or /var/www_backup. An attacker who controls part of the rendered HTML could exploit this to escape the chroot and read sensitive files outside the allowed directory. This issue has been fixed in version 3.16.
Weaknesses (CWE) (1)
  • CWE-20 — Improper Input Validation
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2.3 (LOW)
LOW · 23.6/100
0.3% prob · 26th pct
3.1.6
2026-07-22
2026-07-22
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:dompdf_project:dompdf:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock

framework-component laravel/socialite 5.16.0 (18)

Indirect (18)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
HIGH
HIGH 8.2
EPSS: 31%
Published: 2026-03-19
CVE-2026-32935
exact
composer:
phpseclib/phpseclib
3.0.42 direct
defined in: bookstackapp/bookstack
CWE-208
Observable Timing Discrepancy
phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. — nvdosvpackagist
Description
phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50.
Weaknesses (CWE) (1)
  • CWE-208 — Observable Timing Discrepancy
Metadata
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.2 (HIGH)
HIGH · 71.9/100
0.4% prob · 31th pct
2026-03-19
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
  • cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
  • cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 7.5
EPSS: 10%
Published: 2026-05-05
CVE-2026-44167
exact
composer:
phpseclib/phpseclib
3.0.42 direct
defined in: bookstackapp/bookstack
CWE-400
Uncontrolled Resource Consumption (DoS)
phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a bypass of CVE-2024-27355. — nvdosvpackagist
Description
phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a bypass of CVE-2024-27355. This vulnerability is fixed in 1.0.29, 2.0.54, and 3.0.52.
Weaknesses (CWE) (1)
  • CWE-400 — Uncontrolled Resource Consumption (DoS)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
MEDIUM · 62.1/100
0.2% prob · 10th pct
2026-05-05
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 7.2
EPSS: 12%
Published: 2026-08-03
CVE-2026-69246
exact
composer:
guzzlehttp/guzzle
7.9.2 direct
defined in: bookstackapp/bookstack
CWE-180 CWE-436
Interpretation Conflict
+2
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. 7.15.2 nvdosvpackagist
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable build, applying IDNA mapping, and uses the result to resolve, connect, name the TLS peer and address a proxy CONNECT, while the supplied Host suppresses the aligned one libcurl would have generated. For a URI host written as 127.0.0.%31, filter_var() rejects the host as an IP literal, yet libcurl decodes it to 127.0.0.1 and reaches loopback with no DNS lookup while the server receives Host: 127.0.0.%31. An attacker who influences a fetched URI can therefore reach a host the application's checks excluded and read whatever the host exposes of the response. The same divergence moves Guzzle's own decisions onto a spelling the transport does not use: no_proxy selects proxy routing from the literal host, and RedirectMiddleware decides from it whether to strip Authorization and Cookie. Exploitation requires the application to build a request URI from untrusted input and to make a host decision before handing it to Guzzle. This issue is fixed in versions 7.15.2 and 8.0.1.
Weaknesses (CWE) (4)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
7.2 (HIGH)
MEDIUM · 60/100
0.2% prob · 12th pct
7.15.2
2026-08-03
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
LOW 6.5
EPSS: 3%
Published: 2025-07-31
CVE-2025-45769
exact
composer:
firebase/php-jwt
6.10.1 direct
defined in: bookstackapp/bookstack
CWE-326
Inadequate Encryption Strength
php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. 7.0.0 nvdosvpackagist
Description
php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.
Weaknesses (CWE) (1)
  • CWE-326 — Inadequate Encryption Strength
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
6.5 (LOW)
MEDIUM · 52.7/100
0.1% prob · 3th pct
7.0.0
2025-07-31
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:google:firebase_php-jwt:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 6.5
EPSS: 3%
Published: 2026-08-03
CVE-2026-69245
exact
composer:
guzzlehttp/guzzle
7.9.2 direct
defined in: bookstackapp/bookstack
CWE-180 CWE-346
Origin Validation Error
+1
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, … 7.15.2 nvdosvpackagist
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two spellings a transport reads as an address keep subdomain scope. Hexadecimal and mixed-base forms such as 0x7f000001 and 0177.0.0.0x1 go unrecognized while libcurl 8.21.0 reads both as 127.0.0.1. A percent-escaped Domain keeps that scope on both branches because percent-decoding sits above numeric parsing, so 192.168.0.%31 and 127.0.0.1%2e are registered names in the URI grammar rather than address literals, and no numeric rule in any base classifies them, while libcurl decodes the host before resolving and reads them as 192.168.0.1 and 127.0.0.1. A cookie stored for Domain=0x7f000001 is placed in the Cookie header of a request to evil.0x7f000001, disclosing a session identifier or token to a host that is not that address, and a response from evil.0x7f000001 setting Domain=0x7f000001 is accepted into the jar and replayed to the address, so a server answering for the look-alike name can fix a session or set application state. Exploitation requires the application to enable cookie support, address an origin by one of these spellings, and contact a host whose name ends in that spelling. This issue is fixed in versions 7.15.2 and 8.0.1.
Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
6.5 (MEDIUM)
MEDIUM · 52.7/100
0.1% prob · 3th pct
7.15.2
2026-08-03
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.9
EPSS: 17%
Published: 2026-07-20
CVE-2026-67354
exact
composer:
guzzlehttp/guzzle
7.9.2 direct
defined in: bookstackapp/bookstack
CWE-201 guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. 7.15.1 nvdosvpackagist
Description
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redirect (e.g., HTTPS to HTTPS). An attacker who controls the redirect destination can read this fragment from the incoming Referer header, potentially disclosing one-time login secrets, access tokens, state values, or other sensitive client data to a server never meant to receive it. The referer setting is disabled by default. Fixed in 7.15.1, which strips the fragment before generating the Referer value.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.9 (MEDIUM)
MEDIUM · 50.6/100
0.3% prob · 17th pct
7.15.1
2026-07-20
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.9
EPSS: 14%
Published: 2026-07-20
CVE-2026-67355
exact
composer:
guzzlehttp/guzzle
7.9.2 direct
defined in: bookstackapp/bookstack
CWE-201 guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. 7.15.1 nvdosvpackagist
Description
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.9 (MEDIUM)
MEDIUM · 50/100
0.2% prob · 14th pct
7.15.1
2026-07-20
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.8
EPSS: 12%
Published: 2026-06-16
CVE-2026-55599
exact
composer:
phpseclib/phpseclib
3.0.42 direct
defined in: bookstackapp/bookstack
CWE-918
Server-Side Request Forgery (SSRF)
phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Auth… — nvdosvpackagist
Description
phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension and connects to it. Attacker who supplies certificate fully controls host, port, and path of that connection. URL fetching is enabled by default, and no destination is blocked. An unauthenticated attacker can therefore make a validating server open connections to internal hosts and ports it should never reach, for example loopback 127.0.0.1, cloud metadata address 169.254.169.254, and internal-only services. This is a server-side request forgery (SSRF) caused by an insecure default. This vulnerability is fixed in 1.0.30, 2.0.55, and 3.0.54.
Weaknesses (CWE) (1)
  • CWE-918 — Server-Side Request Forgery (SSRF)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
5.8 (MEDIUM)
MEDIUM · 48.8/100
0.2% prob · 12th pct
2026-06-16
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
  • cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
  • cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.8
EPSS: 12%
Published: 2026-06-18
CVE-2026-55767
exact
composer:
guzzlehttp/guzzle
7.9.2 direct
defined in: bookstackapp/bookstack
CWE-346
Origin Validation Error
CWE-1286
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. 7.12.1 nvdosvpackagist
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string; SetCookie::validate() only rejected a strictly empty domain, so these cookies could be stored and the empty normalized domain was treated as matching any request host. An attacker-controlled origin that an application requests with a shared cookie jar can therefore set a cookie that Guzzle later sends to unrelated hosts using the same jar. This may allow cookie injection or session fixation against downstream services, depending on how those services interpret the injected cookie. This vulnerability is fixed in 7.12.1.
Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
5.8 (MEDIUM)
MEDIUM · 48.7/100
0.2% prob · 12th pct
7.12.1
2026-06-18
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.9
EPSS: 4%
Published: 2026-06-18
CVE-2026-55568
exact
composer:
guzzlehttp/guzzle
7.9.2 direct
defined in: bookstackapp/bookstack
CWE-311
Missing Encryption of Sensitive Data
CWE-319
Cleartext Transmission of Sensitive Information
+1
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. 7.12.1 nvdosvpackagist
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or CURLOPT_PROXYUSERPWD) are sent without encryption, and the CONNECT target host and port for tunneled HTTPS requests are exposed. The built-in cURL handlers (GuzzleHttp\Handler\CurlHandler and GuzzleHttp\Handler\CurlMultiHandler, used by default whenever the PHP cURL extension is available) accept an https:// proxy. libcurl older than 7.50.2 silently treats an https:// proxy as a plaintext http:// proxy. The TLS connection to the proxy is never established, and the proxy leg is cleartext with no error or warning. An application is affected when it sends requests through one of the built-in cURL handlers, configures an https:// proxy expecting the proxy connection itself to be encrypted, and runs with libcurl older than 7.50.2. This vulnerability is fixed in 7.12.1.
Weaknesses (CWE) (3)
  • CWE-311 — Missing Encryption of Sensitive Data
  • CWE-319 — Cleartext Transmission of Sensitive Information
  • CWE-636 (unknown weakness)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
5.9 (MEDIUM)
MEDIUM · 48.1/100
0.1% prob · 4th pct
7.12.1
2026-06-18
2026-09-10
exact
nvd+osv+packagist
External links (1)
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 16%
Published: 2026-07-20
CVE-2026-67353
exact
composer:
guzzlehttp/guzzle
7.9.2 direct
defined in: bookstackapp/bookstack
CWE-770
Allocation of Resources Without Limits or Throttling
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. 7.15.1 nvdosvpackagist
Description
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.
Weaknesses (CWE) (1)
  • CWE-770 — Allocation of Resources Without Limits or Throttling
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (MEDIUM)
MEDIUM · 45.7/100
0.2% prob · 16th pct
7.15.1
2026-07-20
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 14%
Published: 2026-07-20
CVE-2026-67339
exact
composer:
guzzlehttp/guzzle
7.9.2 direct
defined in: bookstackapp/bookstack
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. 7.14.2 nvdosvpackagist
Description
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.
Weaknesses (CWE) (1)
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (MEDIUM)
MEDIUM · 45.3/100
0.2% prob · 14th pct
7.14.2
2026-07-20
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 10%
Published: 2026-05-25
CVE-2026-48998
exact
composer:
guzzlehttp/psr7
2.7.0 direct
defined in: bookstackapp/bookstack
CWE-20
Improper Input Validation
CWE-918
Server-Side Request Forgery (SSRF)
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. 2.10.2 nvdosvpackagist
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. An attacker can provide a malformed Host header containing URI authority delimiters, such as `trusted.example@evil.example`. When the Host value is used to construct a URI, the malformed value can be reinterpreted as URI userinfo and host. This can cause the PSR-7 request URI host to differ from the original Host header value. Applications are affected if they parse attacker-controlled raw HTTP requests with `GuzzleHttp\Psr7\Message::parseRequest()` or the legacy 1.x `GuzzleHttp\Psr7\parse_request()` function, or if they build server requests from attacker-controlled server variables, then rely on the resulting URI host for routing, allow-list checks, or forwarding decisions. In affected forwarding or gateway scenarios, this may cause requests or credentials to be sent to an unintended host. The issue is patched in `2.10.2`. `1.x` is end-of-life and will not receive a patch. Some workarounds are available. Validate the `Host` header as `uri-host [ ":" port ]` before calling `Message::parseRequest()` or legacy `parse_request()` on untrusted HTTP request data, or before deriving routing and forwarding decisions from a parsed request URI. Reject Host values containing userinfo, path, query, or fragment delimiters.
Weaknesses (CWE) (2)
  • CWE-20 — Improper Input Validation
  • CWE-918 — Server-Side Request Forgery (SSRF)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3 (MEDIUM)
MEDIUM · 44.4/100
0.2% prob · 10th pct
2.10.2
2026-05-25
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 9%
Published: 2026-05-25
CVE-2026-49214
exact
composer:
guzzlehttp/psr7
2.7.0 direct
defined in: bookstackapp/bookstack
CWE-20
Improper Input Validation
CWE-93
CRLF Injection
+1
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. 2.10.2 nvdosvpackagist
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 `Uri` or `Request`. Third, the host component contains CRLF or another header-unsafe character. Fourth, the host is copied into the PSR-7 `Host` header when no explicit `Host` header is provided. Finally, the request is serialized or sent by an HTTP client that does not independently reject the malformed host. In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing `"\r\nX-Injected: yes"` can cause the generated `Host` header to span multiple HTTP header lines. Applications are affected when they use user-controlled URLs for outbound HTTP requests, URL forwarding, proxying, crawling, webhook delivery, or similar request-dispatch flows. In deployments involving HTTP/1.1 connection reuse, proxies, gateways, or load balancers, this malformed request may also contribute to request smuggling or cache poisoning, depending on how downstream components parse the request. The issue is patched in `2.10.2` and later. `1.x` is end-of-life and will not receive a patch. As a workaround, validate and reject all untrusted URI strings before constructing PSR-7 `Uri` or `Request` instances. Reject input containing ASCII control characters, whitespace, or DEL, including CRLF, tab, space, NUL, or DEL characters. Applications that forward requests should also ensure the final HTTP client or serializer rejects invalid URI and header data before writing requests to the network.
Weaknesses (CWE) (3)
  • CWE-20 — Improper Input Validation
  • CWE-93 — CRLF Injection
  • CWE-113 — HTTP Response Splitting
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
5.3 (MEDIUM)
MEDIUM · 44.2/100
0.2% prob · 9th pct
2.10.2
2026-05-25
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
MEDIUM 4.8
EPSS: 14%
Published: 2026-06-18
CVE-2026-55766
exact
composer:
guzzlehttp/psr7
2.7.0 direct
defined in: bookstackapp/bookstack
CWE-93
CRLF Injection
CWE-113
HTTP Response Splitting
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason… 2.12.1 nvdosvpackagist
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason phrase. If an application placed attacker-controlled data into one of those fields and later serialized the PSR-7 message as raw HTTP/1.x, for example with Message::toString() or an equivalent serializer, the serialized message could contain attacker-controlled header lines. The issue can also be reached through Message::parseRequest() or Message::parseResponse() when malformed raw messages are parsed into first-party PSR-7 objects and then serialized again. Creating or modifying a Request, Response, or other PSR-7 object alone is not sufficient. The issue requires the malformed message to be serialized and written to the network, forwarded, replayed, or otherwise processed by software that does not independently reject the malformed start line. This vulnerability is fixed in 2.12.1.
Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
4.8 (MEDIUM)
MEDIUM · 41.2/100
0.2% prob · 14th pct
2.12.1
2026-06-18
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
LOW
MEDIUM 4.7
EPSS: 6%
Published: 2026-07-20
CVE-2026-59883
exact
composer:
guzzlehttp/guzzle
7.9.2 direct
defined in: bookstackapp/bookstack
CWE-346
Origin Validation Error
CWE-384
Session Fixation
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matc… 7.12.3 nvdosvpackagist
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.
Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
4.7 (MEDIUM)
LOW · 38.9/100
0.2% prob · 6th pct
7.12.3
2026-07-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
LOW
MEDIUM 4.2
EPSS: 25%
Published: 2026-07-21
CVE-2026-59882
exact
composer:
guzzlehttp/psr7
2.7.0 direct
defined in: bookstackapp/bookstack
CWE-436
Interpretation Conflict
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::ge… 2.12.3 nvdosvpackagist
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.
Weaknesses (CWE) (1)
  • CWE-436 — Interpretation Conflict
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
4.2 (MEDIUM)
LOW · 38.6/100
0.3% prob · 25th pct
2.12.3
2026-07-21
2026-07-21
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
LOW
LOW 3.7
EPSS: 30%
Published: 2026-04-10
CVE-2026-40194
exact
composer:
phpseclib/phpseclib
3.0.42 direct
defined in: bookstackapp/bookstack
CWE-208
Observable Timing Discrepancy
phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operator to compare a received SSH packet HMAC against the locally computed H… 3.0.51 nvdosvpackagist
Description
phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operator to compare a received SSH packet HMAC against the locally computed HMAC. != on equal-length binary strings in PHP uses memcmp(), which short-circuits on the first differing byte. This is a real variable-time comparison (CWE-208), proven by scaling benchmarks. This vulnerability is fixed in 3.0.51, 2.0.53, and 1.0.28.
Weaknesses (CWE) (1)
  • CWE-208 — Observable Timing Discrepancy
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
3.7 (LOW)
LOW · 35.6/100
0.4% prob · 30th pct
3.0.51
2026-04-10
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
  • cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
  • cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock

framework-component laravel/tinker 2.10.0 (1)

Indirect (1)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
MEDIUM
MEDIUM 6.7
EPSS: 23%
Published: 2026-01-30
CVE-2026-25129
exact
composer:
psy/psysh
0.12.4 direct
defined in: bookstackapp/bookstack
CWE-427
Uncontrolled Search Path Element
PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. — nvdosvpackagist
Description
PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as their CWD when launching PsySH, the attacker can trigger arbitrary code execution in the victim's context. When the victim runs PsySH with elevated privileges (e.g., root), this results in local privilege escalation. This is a CWD configuration poisoning issue leading to arbitrary code execution in the victim user’s context. If a privileged user (e.g., root, a CI runner, or an ops/debug account) launches PsySH with CWD set to an attacker-writable directory containing a malicious `.psysh.php`, the attacker can execute commands with that privileged user’s permissions, resulting in local privilege escalation. Downstream consumers that embed PsySH inherit this risk. For example, Laravel Tinker (`php artisan tinker`) uses PsySH. If a privileged user runs Tinker while their shell is in an attacker-writable directory, the `.psysh.php` auto-load behavior can be abused in the same way to execute attacker-controlled code under the victim’s privileges. Versions 0.11.23 and 0.12.19 patch the issue.
Weaknesses (CWE) (1)
  • CWE-427 — Uncontrolled Search Path Element
Metadata
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
6.7 (MEDIUM)
MEDIUM · 58.1/100
0.3% prob · 23th pct
2026-01-30
2026-02-03
exact
nvd+osv+packagist
Affected CPE configurations (2)
  • cpe:2.3:a:psysh:psysh:*:*:*:*:*:*:*:*
  • cpe:2.3:a:psysh:psysh:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock

symfony · symfony-demo (67)

Warnings (3)

CMS_RECIPE_ORPHANED (3)
symfony:symfony-demo: symfony.lock recipe doctrine/common has no matching installed Composer package
symfony:symfony-demo: symfony.lock recipe friendsofphp/proxy-manager-lts has no matching installed Composer package
symfony:symfony-demo: symfony.lock recipe laminas/laminas-code has no matching installed Composer package

bundle doctrine/doctrine-bundle 2.12.0, bundle doctrine/doctrine-migrations-bundle 3.3.1, framework-component symfony/cache 7.1.1, framework-component symfony/expression-language 7.1.1, framework symfony/framework-bundle 7.1.1, bundle twig/extra-bundle 3.10.0, bundle dama/doctrine-test-bundle 8.2.0, bundle doctrine/doctrine-fixtures-bundle 3.6.1, bundle symfony/maker-bundle 1.59.1, framework-component symfony/web-profiler-bundle 7.1.1 (1)

Direct (1)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
MEDIUM
MEDIUM 6.3
EPSS: 39%
Published: 2026-05-20
CVE-2026-45073
exact
composer:
symfony/cache
7.1.1 direct
defined in: symfony/symfony-demo
CWE-89
SQL Injection
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence $prefix to break out of the LIKE literal and alter query semantics or deletion scope. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (MEDIUM)
MEDIUM · 58.2/100
0.5% prob · 39th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework-component symfony/asset-mapper 7.1.1, framework-component symfony/http-client 7.1.1, bundle symfonycasts/sass-bundle 0.3.0 (1)

Direct (1)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
LOW
LOW 3.1
EPSS: 40%
Published: 2024-11-13
CVE-2024-50342
exact
composer:
symfony/http-client
7.1.1 direct
defined in: symfony/symfony-demo
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. 7.1.8 nvdosvpackagist
Description
symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Weaknesses (CWE) (1)
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
3.1 (LOW)
LOW · 32.8/100
0.5% prob · 40th pct
7.1.8
2024-11-13
2026-02-03
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:sensiolabs:httpclient:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:httpclient:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:httpclient:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework symfony/framework-bundle 7.1.1 (27)

Indirect (27)

Priority / severityAdvisory IDDependencyCWEDescriptionFix VersionSource
HIGH
MEDIUM 7.3
EPSS: 99%
Published: 2024-11-05
CVE-2024-50340
exact
composer:
symfony/runtime
7.1.1 direct
defined in: symfony/symfony-demo
CWE-74
Improper Neutralization of Special Elements (Injection)
symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. 7.1.7 nvdosvpackagist
Description
symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.14, and 7.1.7 the `SymfonyRuntime` now ignores the `argv` values for non-SAPI PHP runtimes. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Weaknesses (CWE) (1)
  • CWE-74 — Improper Neutralization of Special Elements (Injection)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.3 (MEDIUM)
HIGH · 78.2/100
64.8% prob · 99th pct
7.1.7
2024-11-05
2024-11-07
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
HIGH
HIGH 7.5
Published: 2026-08-06
GHSA-g2gp-3wwq-f4ph
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
— league/commonmark: Denial of service via adjacent inline attribute blocks ### Impact With the Attributes extension enabled, `AttributesListener::findTargetAndDirection()` resolves each attribute node's target by walking outward through it… 2.9.0 osvpackagist
Description
league/commonmark: Denial of service via adjacent inline attribute blocks ### Impact With the Attributes extension enabled, `AttributesListener::findTargetAndDirection()` resolves each attribute node's target by walking outward through its siblings. For a run of N adjacent inline attribute blocks placed at the start of a block (with nothing to their left), each node scans the **entire** sibling list to the far-right end before giving up and falling back to the parent. Each resolution is therefore Θ(N) and the whole run is **Θ(N²)**. Reaching the path requires `AttributesExtension` (opt-in, but first-party: `League\CommonMark\Extension\Attributes\AttributesExtension`). No other configuration matters — the quadratic walk runs unconditionally during parsing and is **not** gated by the `attributes/allow` allow-list, the `on*` hardening added in 2.7.0, or `allow_unsafe_links`. An unauthenticated attacker can submit a **~32 KB** input (`{#a}` repeated 8,000 times) that takes **over 5 seconds** to convert, with time growing quadratically in input length — a cheap denial of service. Availability impact only. **The Attributes extension was introduced in 1.5.0 (May 2020) with this outward-walk resolver present from the first commit, so all releases from 1.5.0 onward (including every 2.x) are affected.** ### Workarounds There is no library-level configuration that gates the quadratic walk. Integrators who cannot upgrade can only reduce exposure indirectly: - **Disable the Attributes extension** for untrusted input, or - **Impose a strict maximum input length before conversion** — noting that because the cost is quadratic, even a modest cap must be small to meaningfully bound worst-case CPU. Upgrading to a release containing the fix is recommended.
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
HIGH · 75/100
2.9.0
2026-08-06
2026-08-06
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
HIGH
HIGH 7.5
Published: 2026-08-06
GHSA-jfm3-95jq-q3rf
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
— league/commonmark: Denial of service via duplicate footnote definitions ### Impact The Footnote extension records one backref per footnote *reference* and then appends the **entire** backref list for **every** footnote *definition* block… 2.9.0 osvpackagist
Description
league/commonmark: Denial of service via duplicate footnote definitions ### Impact The Footnote extension records one backref per footnote *reference* and then appends the **entire** backref list for **every** footnote *definition* block in the document, without ever de-duplicating or removing repeated definitions of the same label (`GatherFootnotesListener`, populated by `NumberFootnotesListener`). A document that references a single label N times and also supplies N duplicate `[^a]:` definitions of that label therefore produces **N × N** `FootnoteBackref` nodes, so output size, parse time, and peak memory are all **O(N²)**. Reaching the vulnerable path requires `FootnoteExtension` to be registered on the `Environment`. This is opt-in, but is a commonly enabled GFM-style feature; no other non-default configuration is required. An unauthenticated attacker can expand a **~10 KB** request into a **~62 MB** HTML response, **~3 s** of CPU, and **~440 MB** of peak memory — enough to OOM-kill a default 128 MB PHP worker and deny service. Availability impact only; no confidentiality or integrity effect. **The Footnote extension was introduced in 1.5.0 (May 2020) with this backref logic present from the first commit, so all releases from 1.5.0 onward (including every 2.x through 2.8.x) are affected.** ### Workarounds There is no library-level option to cap the number of footnotes, references, or definitions, so no configuration switch prevents the amplification. Integrators who cannot upgrade should: - **Disable the Footnote extension** for untrusted input, or - **Enforce a strict input-size limit before conversion** — but note this is a weak control here, since the ~10 KB payload that already triggers the 62 MB / ~440 MB blowup is well within typical request-body limits, so any cap must be aggressively small to help. Upgrading to the patched release is the recommended remediation.
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
HIGH · 75/100
2.9.0
2026-08-06
2026-08-06
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
HIGH
HIGH 7.5
Published: 2026-08-06
GHSA-mh25-x5hq-wrqp
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
— league/commonmark: Denial of service via colliding heading slugs ### Impact `UniqueSlugNormalizer::normalize()` makes each slug document-unique by searching for an unused numeric suffix, but **restarts that search from `1` on every collis… 2.9.0 osvpackagist
Description
league/commonmark: Denial of service via colliding heading slugs ### Impact `UniqueSlugNormalizer::normalize()` makes each slug document-unique by searching for an unused numeric suffix, but **restarts that search from `1` on every collision**. The k-th heading that collapses to the same base slug performs k−1 array lookups, so K colliding slugs cost Σ(k−1) = **O(K²)**. An attacker can force every heading onto a single base slug trivially — many empty ATX headings, identical heading text, or punctuation-only headings that normalize to the empty string. The path is reached whenever the shared slug normalizer runs over attacker-controlled text. That happens when `HeadingPermalinkExtension` is registered (its `HeadingPermalinkProcessor` normalizes every heading), independently through `FootnoteExtension` (its `AnonymousFootnoteRefParser` normalizes every `^[label]` reference), and on any `TableOfContentsExtension` site (which requires `HeadingPermalinkExtension` to be co-registered). The default `slug_normalizer/unique` setting (`UniqueSlugNormalizerInterface::PER_DOCUMENT`) accumulates collisions across the whole document. No authentication is required — a small document body turns into seconds of CPU and denies service. Availability impact only. **`UniqueSlugNormalizer` was introduced in 2.0.0 (first shipped in 2.0.0-beta1, May 2021); the 1.x heading-permalink slug generator performed no de-duplication and is not affected. All 2.x releases (including 2.8.x) are affected.** ### Workarounds Integrators who cannot upgrade immediately can: - **Set `slug_normalizer/unique` to `false` / `UniqueSlugNormalizerInterface::DISABLED`**, which stops the de-duplication scan entirely — at the cost of losing id uniqueness (colliding headings then share an anchor). - **Disable `HeadingPermalinkExtension`** (and `TableOfContentsExtension`, which depends on it), and `FootnoteExtension` where anonymous footnotes reach the same normalizer, for untrusted Markdown. - **Cap the accept…
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
HIGH · 75/100
2.9.0
2026-08-06
2026-08-06
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
HIGH 7.5
EPSS: 28%
Published: 2026-08-06
CVE-2026-71488
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
CWE-407
Inefficient Algorithmic Complexity
CWE-1050
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths… 2.9.0 nvdosvpackagist
Description
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate the remaining line at every URL-like prefix, allowing an attacker who can submit Markdown for conversion to consume disproportionate CPU time with a comparatively small request. This issue is fixed in 2.9.0.
Weaknesses (CWE) (2)
  • CWE-407 — Inefficient Algorithmic Complexity
  • CWE-1050 (unknown weakness)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
MEDIUM · 65.6/100
0.3% prob · 28th pct
2.9.0
2026-08-06
2026-08-21
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
HIGH 7.5
EPSS: 22%
Published: 2026-09-01
CVE-2026-86429
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
CWE-407
Inefficient Algorithmic Complexity
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. 2.9.1 nvdosvpackagist
Description
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can submit small, specially crafted Markdown documents — such as text alternating with unpaired quotes, contiguous runs of block-level attribute blocks, or repeated class attributes — to trigger disproportionate CPU consumption and cause a denial of service. Fixed in 2.9.1.
Weaknesses (CWE) (1)
  • CWE-407 — Inefficient Algorithmic Complexity
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.5 (HIGH)
MEDIUM · 64.4/100
0.3% prob · 22th pct
2.9.1
2026-09-01
2026-09-08
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
HIGH 7.5
EPSS: 21%
Published: 2026-09-01
CVE-2026-86430
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
CWE-407
Inefficient Algorithmic Complexity
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. 2.9.1 nvdosvpackagist
Description
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing.
Weaknesses (CWE) (1)
  • CWE-407 — Inefficient Algorithmic Complexity
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.5 (HIGH)
MEDIUM · 64.2/100
0.3% prob · 21th pct
2.9.1
2026-09-01
2026-09-08
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
HIGH 7.5
EPSS: 21%
Published: 2024-12-09
CVE-2024-58382
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
CWE-407
Inefficient Algorithmic Complexity
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. 2.6.0 nvdosvpackagist
Description
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs designed to trigger worst-case performance, and sending multiple requests in parallel exhausts CPU resources and PHP-FPM processes.
Weaknesses (CWE) (1)
  • CWE-407 — Inefficient Algorithmic Complexity
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.5 (HIGH)
MEDIUM · 64.1/100
0.3% prob · 21th pct
2.6.0
2024-12-09
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
HIGH 7.5
EPSS: 21%
Published: 2026-09-01
CVE-2026-86428
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
CWE-407
Inefficient Algorithmic Complexity
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. 2.10.0 nvdosvpackagist
Description
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing.
Weaknesses (CWE) (1)
  • CWE-407 — Inefficient Algorithmic Complexity
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.5 (HIGH)
MEDIUM · 64.1/100
0.3% prob · 21th pct
2.10.0
2026-09-01
2026-09-08
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 6.9
EPSS: 35%
Published: 2026-05-29
CVE-2026-49208
exact
composer:
symfony/ux-live-component
2.17.0 direct
defined in: symfony/symfony-demo
CWE-20
Improper Input Validation
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, Symfony\UX\LiveComponent\LiveComponentHydrator::hydrateObjectValue()… 2.36.0 nvdosvpackagist
Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, Symfony\UX\LiveComponent\LiveComponentHydrator::hydrateObjectValue() falls back to new $className($value), allowing client-supplied relative strings such as now, tomorrow, or +10 years to move a writable, format-less date prop past time-based business logic checks. This issue is fixed in versions 2.36.0 and 3.1.0.
Weaknesses (CWE) (1)
  • CWE-20 — Improper Input Validation
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.9 (MEDIUM)
MEDIUM · 62.2/100
0.4% prob · 35th pct
2.36.0
2026-05-29
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (2)
  • cpe:2.3:a:symfony:ux:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:ux:3.0.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
LOW 6.9
EPSS: 16%
Published: 2026-05-29
CVE-2026-49212
exact
composer:
symfony/ux-live-component
2.17.0 direct
defined in: symfony/symfony-demo
CWE-345
Insufficient Verification of Data Authenticity
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the sl… 2.36.0 nvdosvpackagist
Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the slot identifier (props vs propsFromParent), or request context, allowing a signed blob minted for one component or slot to be replayed in another and set a read-only prop on a target component. This issue is fixed in versions 2.36.0 and 3.1.0.
Weaknesses (CWE) (1)
  • CWE-345 — Insufficient Verification of Data Authenticity
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.9 (LOW)
MEDIUM · 58.3/100
0.2% prob · 16th pct
2.36.0
2026-05-29
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (2)
  • cpe:2.3:a:symfony:ux:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:ux:3.0.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 6.4
EPSS: 30%
Published: 2025-05-05
CVE-2025-46734
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
CWE-79
Cross-site Scripting (XSS)
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls … 2.7.0 nvdosvpackagist
Description
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls into HTML. The league/commonmark library provides configuration options such as `html_input: 'strip'` and `allow_unsafe_links: false` to mitigate cross-site scripting (XSS) attacks by stripping raw HTML and disallowing unsafe links. However, when the Attributes Extension is enabled, it introduces a way for users to inject arbitrary HTML attributes into elements via Markdown syntax using curly braces. Version 2.7.0 contains three changes to prevent this XSS attack vector: All attributes starting with `on` are considered unsafe and blocked by default; support for an explicit allowlist of allowed HTML attributes; and manually-added `href` and `src` attributes now respect the existing `allow_unsafe_links` configuration option. If upgrading is not feasible, please consider disabling the `AttributesExtension` for untrusted users and/or filtering the rendered HTML through a library like HTMLPurifier.
Weaknesses (CWE) (1)
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
6.4 (MEDIUM)
MEDIUM · 57.2/100
0.4% prob · 30th pct
2.7.0
2025-05-05
2026-03-20
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 6.3
EPSS: 16%
Published: 2026-03-19
CVE-2026-33347
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
CWE-79
Cross-site Scripting (XSS)
CWE-185
Incorrect Regular Expression
+1
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matchi… — nvdosvpackagist
Description
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.
Weaknesses (CWE) (3)
  • CWE-79 — Cross-site Scripting (XSS)
  • CWE-185 — Incorrect Regular Expression
  • CWE-918 — Server-Side Request Forgery (SSRF)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (MEDIUM)
MEDIUM · 53.5/100
0.2% prob · 16th pct
2026-03-19
2026-03-27
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 5.3
Published: 2026-08-06
GHSA-mj63-m3rc-8ppr
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
— league/commonmark: Denial of service via deeply nested XML output ### Impact `XmlRenderer` pretty-prints XML by emitting depth-proportional indentation whitespace for **every** opening and closing tag. 2.9.0 osvpackagist
Description
league/commonmark: Denial of service via deeply nested XML output ### Impact `XmlRenderer` pretty-prints XML by emitting depth-proportional indentation whitespace for **every** opening and closing tag. For a tree of depth n, the indentation alone sums to **O(n²)** bytes of output (and corresponding memory), reachable through `MarkdownToXmlConverter` — e.g. `str_repeat('> ', $depth) . "x\n"`, a single line of nested blockquotes — or through a direct `XmlRenderer::renderDocument()` call on an attacker-influenced AST. This affects applications that convert untrusted Markdown to XML, which is an **opt-in** output path. The parser's `max_nesting_level` bounds the depth of *parser-created* trees, but its default is high enough to reach damaging sizes, can be raised by the host application, and does not constrain custom or programmatically built ASTs handed straight to the renderer. The result is a memory / output-size amplification rather than a hard crash, which is why this issue is rated **Medium** rather than High. No confidentiality or integrity impact. XML rendering was introduced in 2.0.0 (first shipped in 2.0.0-beta1, June 2021) and has emitted depth-proportional indentation ever since, so all 2.x releases are affected (verified against 2.8.x, clean upstream `1902f60f`). 1.x has no XML renderer and is not affected. ### Workarounds Applications converting untrusted Markdown to XML should: - **Lower `max_nesting_level`** to a conservative value appropriate to expected content, so the parser refuses to build extremely deep trees. This is the most direct lever for parser-produced ASTs, but does not protect trees built programmatically and passed straight to `XmlRenderer`. - **Cap input size before conversion**, since the amplification is driven by input-proportional depth. - **Constrain XML consumers** with memory / output-size limits (and streaming or size caps on any downstream XML parser or storage) so one request cannot allocate unbounded output. - **Prefer H…
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
5.3 (MEDIUM)
MEDIUM · 53/100
2.9.0
2026-08-06
2026-08-06
exact
osv+packagist
External links (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 6.1
EPSS: 16%
Published: 2026-08-06
CVE-2026-71478
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
CWE-79
Cross-site Scripting (XSS)
CWE-86 +1
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, … — nvdosvpackagist
Description
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0.
Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 (MEDIUM)
MEDIUM · 52/100
0.2% prob · 16th pct
2026-08-06
2026-08-21
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 6.1
EPSS: 16%
Published: 2025-05-19
CVE-2025-47946
exact
composer:
symfony/ux-live-component
2.17.0 direct
defined in: symfony/symfony-demo
CWE-79
Cross-site Scripting (XSS)
Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. 2.25.1 nvdosvpackagist
Description
Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. `only()`, `defaults()`, `without()`) ouputs attribute values directly without escaping. If these values are unsafe (e.g. contain user input), this can lead to HTML attribute injection and XSS vulnerabilities. The issue is fixed in version `2.25.1` of `symfony/ux-twig-component` Those who use `symfony/ux-live-component` must also update it to `2.25.1` to benefit from the fix, as it reuses the `ComponentAttributes` class internally. As a workaround, avoid rendering `{{ attributes }}` or derived objects directly if it may contain untrusted values. Instead, use `{{ attributes.render('name') }}` for safe output of individual attributes.
Weaknesses (CWE) (1)
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 (MEDIUM)
MEDIUM · 51.9/100
0.2% prob · 16th pct
2.25.1
2025-05-19
2025-08-29
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 6.1
EPSS: 16%
Published: 2025-05-19
CVE-2025-47946
exact
composer:
symfony/ux-twig-component
2.17.0 direct
defined in: symfony/symfony-demo
CWE-79
Cross-site Scripting (XSS)
Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. 2.25.1 nvdosvpackagist
Description
Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. `only()`, `defaults()`, `without()`) ouputs attribute values directly without escaping. If these values are unsafe (e.g. contain user input), this can lead to HTML attribute injection and XSS vulnerabilities. The issue is fixed in version `2.25.1` of `symfony/ux-twig-component` Those who use `symfony/ux-live-component` must also update it to `2.25.1` to benefit from the fix, as it reuses the `ComponentAttributes` class internally. As a workaround, avoid rendering `{{ attributes }}` or derived objects directly if it may contain untrusted values. Instead, use `{{ attributes.render('name') }}` for safe output of individual attributes.
Weaknesses (CWE) (1)
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 (MEDIUM)
MEDIUM · 51.9/100
0.2% prob · 16th pct
2.25.1
2025-05-19
2025-08-29
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
LOW 5.3
EPSS: 45%
Published: 2026-05-29
CVE-2026-49209
exact
composer:
symfony/ux-live-component
2.17.0 direct
defined in: symfony/symfony-demo
CWE-770
Allocation of Resources Without Limits or Throttling
Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-requ… 2.36.0 nvdosvpackagist
Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-request for each entry; because the array size is never bounded, an authenticated client can submit a single _batch request containing thousands of actions and exhaust CPU, memory, and database connections on the application server. This issue is fixed in versions 2.36.0 and 3.1.0.
Weaknesses (CWE) (1)
  • CWE-770 — Allocation of Resources Without Limits or Throttling
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (LOW)
MEDIUM · 51.5/100
0.6% prob · 45th pct
2.36.0
2026-05-29
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (2)
  • cpe:2.3:a:symfony:ux:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:ux:3.0.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
LOW 5.3
EPSS: 45%
Published: 2026-05-20
CVE-2026-46629
exact
composer:
twig/intl-extra
3.10.0 direct
defined in: symfony/symfony-demo
CWE-770
Allocation of Resources Without Limits or Throttling
Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template t… 3.26.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template to allocate many ICU formatter objects that remain pinned for the lifetime of the Twig\Environment. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
  • CWE-770 — Allocation of Resources Without Limits or Throttling
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (LOW)
MEDIUM · 51.3/100
0.5% prob · 45th pct
3.26.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 28%
Published: 2026-05-26
CVE-2026-48761
exact
composer:
symfony/html-sanitizer
7.1.1 direct
defined in: symfony/symfony-demo
CWE-79
Cross-site Scripting (XSS)
CWE-1023
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on <object>, <applet>, <iframe>, and <img>, and <meta http-equiv="refresh"> URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.
Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (MEDIUM)
MEDIUM · 48/100
0.3% prob · 28th pct
7.2.0
2026-05-26
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 5.3
EPSS: 27%
Published: 2026-05-26
CVE-2026-48760
exact
composer:
symfony/html-sanitizer
7.1.1 direct
defined in: symfony/symfony-demo
CWE-451
UI Misrepresentation of Critical Information
CWE-1007
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstream consumers could decode or display. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.
Weaknesses (CWE) (2)
  • CWE-451 — UI Misrepresentation of Critical Information
  • CWE-1007 (unknown weakness)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (MEDIUM)
MEDIUM · 47.9/100
0.3% prob · 27th pct
7.2.0
2026-05-26
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
LOW 5.1
EPSS: 23%
Published: 2026-05-20
CVE-2026-46637
exact
composer:
twig/markdown-extra
3.10.0 direct
defined in: symfony/symfony-demo
CWE-116
Improper Encoding or Escaping of Output
CWE-79
Cross-site Scripting (XSS)
Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, U… 3.26.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (2)
  • CWE-116 — Improper Encoding or Escaping of Output
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.1 (LOW)
MEDIUM · 45.5/100
0.3% prob · 23th pct
3.26.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 5.1
EPSS: 12%
Published: 2026-03-06
CVE-2026-30838
exact
composer:
league/commonmark
2.4.2 direct
defined in: symfony/symfony-demo
CWE-79
Cross-site Scripting (XSS)
league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. — nvdosvpackagist
Description
league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. For example, <script\n> would pass through unfiltered and be rendered as a valid HTML tag by browsers. This is a cross-site scripting (XSS) vector for any application that relies on this extension to sanitize untrusted user input. All applications using the DisallowedRawHtml extension to process untrusted markdown are affected. Applications that use a dedicated HTML sanitizer (such as HTML Purifier) on the rendered output are not affected. This issue has been patched in version 2.8.1.
Weaknesses (CWE) (1)
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.1 (MEDIUM)
MEDIUM · 43.3/100
0.2% prob · 12th pct
2026-03-06
2026-03-20
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
LOW
MEDIUM 2.3
EPSS: 27%
Published: 2026-05-20
CVE-2026-45064
exact
composer:
symfony/html-sanitizer
7.1.1 direct
defined in: symfony/symfony-demo
CWE-451
UI Misrepresentation of Critical Information
CWE-1007
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href and src attributes, allowing sanitized content to display a link destination that visually differs from the actual destination and enabling phishing-style visual spoofing. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (2)
  • CWE-451 — UI Misrepresentation of Critical Information
  • CWE-1007 (unknown weakness)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2.3 (MEDIUM)
LOW · 23.9/100
0.3% prob · 27th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
LOW
MEDIUM 2.3
EPSS: 27%
Published: 2026-05-20
CVE-2026-45066
exact
composer:
symfony/html-sanitizer
7.1.1 direct
defined in: symfony/symfony-demo
CWE-184
Incomplete List of Disallowed Inputs
CWE-436
Interpretation Conflict
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization can allow off-allowlist URLs through allowLinkHosts() or allowMediaHosts() because UrlSanitizer::parse() follows RFC 3986 while browsers follow WHATWG URL parsing, and because <area href> is checked against the media policy rather than the link policy. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (2)
  • CWE-184 — Incomplete List of Disallowed Inputs
  • CWE-436 — Interpretation Conflict
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2.3 (MEDIUM)
LOW · 23.9/100
0.3% prob · 27th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
LOW
MEDIUM 2.3
EPSS: 27%
Published: 2026-05-29
CVE-2026-49210
exact
composer:
symfony/ux-live-component
2.17.0 direct
defined in: symfony/symfony-demo
CWE-79
Cross-site Scripting (XSS)
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubsc… 2.36.0 nvdosvpackagist
Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubscriber and InterceptChildComponentRenderSubscriber directly into HTML as a tag name without escaping or validation, allowing arbitrary HTML, including <script> tags, on any Live Component re-render that contains at least one child component. This issue is fixed in versions 2.36.0 and 3.1.0.
Weaknesses (CWE) (1)
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2.3 (MEDIUM)
LOW · 23.9/100
0.3% prob · 27th pct
2.36.0
2026-05-29
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (2)
  • cpe:2.3:a:symfony:ux:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:ux:3.0.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
LOW
LOW 2.1
EPSS: 27%
Published: 2026-05-20
CVE-2026-45753
exact
composer:
symfony/html-sanitizer
7.1.1 direct
defined in: symfony/symfony-demo
CWE-79
Cross-site Scripting (XSS)
CWE-184
Incomplete List of Disallowed Inputs
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() omits URL-valued attributes including action, formaction, poster, and cite, so configurations that admit those attributes can leave javascript: URIs unsanitized and enable XSS when the resulting HTML is rendered or a victim submits a form or clicks a button. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (2)
  • CWE-79 — Cross-site Scripting (XSS)
  • CWE-184 — Incomplete List of Disallowed Inputs
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2.1 (LOW)
LOW · 22.3/100
0.3% prob · 27th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework-component symfony/http-foundation 7.1.1, framework-component symfony/http-kernel 7.1.1, bundle doctrine/doctrine-bundle 2.12.0, bundle doctrine/doctrine-migrations-bundle 3.3.1, framework symfony/framework-bundle 7.1.1, framework-component symfony/monolog-bridge 7.1.1, bundle symfony/monolog-bundle 3.10.0, framework-component symfony/security-bundle 7.1.1, framework-component symfony/security-http 7.1.1, bundle symfony/stimulus-bundle 2.17.0, framework-component symfony/twig-bundle 7.1.1, bundle twig/extra-bundle 3.10.0, bundle dama/doctrine-test-bundle 8.2.0, bundle doctrine/doctrine-fixtures-bundle 3.6.1, framework-component symfony/debug-bundle 7.1.1, bundle symfony/maker-bundle 1.59.1, framework-component symfony/web-profiler-bundle 7.1.1 (3)

Direct (3)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
HIGH
HIGH 7.3
EPSS: 70%
Published: 2025-11-12
CVE-2025-64500
exact
composer:
symfony/http-foundation
7.1.1 direct
defined in: symfony/symfony-demo
CWE-647 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.
Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.3 (HIGH)
HIGH · 72.3/100
1.3% prob · 70th pct
7.2.0
2025-11-12
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (6)
  • cpe:2.3:a:sensiolabs:httpfoundation:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:httpfoundation:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:httpfoundation:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 6.9
EPSS: 46%
Published: 2026-05-26
CVE-2026-48736
exact
composer:
symfony/http-foundation
7.1.1 direct
defined in: symfony/symfony-demo
CWE-184
Incomplete List of Disallowed Inputs
CWE-918
Server-Side Request Forgery (SSRF)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
Weaknesses (CWE) (2)
  • CWE-184 — Incomplete List of Disallowed Inputs
  • CWE-918 — Server-Side Request Forgery (SSRF)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.9 (MEDIUM)
MEDIUM · 64.4/100
0.6% prob · 46th pct
7.2.0
2026-05-26
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
LOW
LOW 3.1
EPSS: 45%
Published: 2024-11-05
CVE-2024-50345
exact
composer:
symfony/http-foundation
7.1.1 direct
defined in: symfony/symfony-demo
CWE-601
URL Redirection to Untrusted Site (Open Redirect)
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. 7.1.7 nvdosvpackagist
Description
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the `Request` class to redirect users to another domain. The `Request::create` methods now assert the URI does not contain invalid characters as defined by https://url.spec.whatwg.org/. This issue has been patched in versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Weaknesses (CWE) (1)
  • CWE-601 — URL Redirection to Untrusted Site (Open Redirect)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
3.1 (LOW)
LOW · 33.8/100
0.6% prob · 45th pct
7.1.7
2024-11-05
2025-11-03
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework-component symfony/mailer 7.1.1 (1)

Direct (1)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
HIGH
MEDIUM 8.7
EPSS: 43%
Published: 2026-05-20
CVE-2026-45068
exact
composer:
symfony/mailer
7.1.1 direct
defined in: symfony/symfony-demo
CWE-88
Argument Injection
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a -- end-of-options separator, allowing an address beginning with - to be interpreted as a sendmail command-line option instead of an address. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
  • CWE-88 — Argument Injection
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (MEDIUM)
HIGH · 78.3/100
0.5% prob · 43th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework-component symfony/mime 7.1.1, framework-component symfony/mailer 7.1.1 (3)

Direct (2)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
MEDIUM
HIGH 6.3
EPSS: 47%
Published: 2026-05-20
CVE-2026-45067
exact
composer:
symfony/mime
7.1.1 direct
defined in: symfony/symfony-demo
CWE-93
CRLF Injection
### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers… 7.2.0 nvdosvpackagist
Description
### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers treat it as a security boundary. The constructor accepts email addresses whose local-part (the part before `@`) is an RFC-5322 *quoted string* containing raw `\r\n` bytes — e.g. `"x\r\nBcc: attacker@evil"@example.com`. The stored address is later emitted verbatim into (1) the rendered message headers and (2) `SmtpTransport`'s `MAIL FROM:<...>` / `RCPT TO:<...>` protocol lines, turning the embedded CRLF into a new mail header and/or a new SMTP command. ### Resolution The `Address` constructor now rejects addresses containing line breaks. The patch for this issue is available [here](https://github.com/symfony/symfony/commit/dc2dbd29211eb4ddc451373fa1374fb926e94604) for branch 5.4. ### Credits We would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (HIGH)
MEDIUM · 59.9/100
0.6% prob · 47th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 6.3
EPSS: 33%
Published: 2026-05-20
CVE-2026-45070
exact
composer:
symfony/mime
7.1.1 direct
defined in: symfony/symfony-demo
CWE-93
CRLF Injection
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3 (MEDIUM)
MEDIUM · 57/100
0.4% prob · 33th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

Indirect (1)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
MEDIUM
LOW 6.9
EPSS: 44%
Published: 2026-05-26
CVE-2026-46644
exact
composer:
symfony/polyfill-intl-idn
1.29.0 direct
defined in: symfony/symfony-demo
CWE-1289 Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. 1.38.1 nvdosvpackagist
Description
Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33 requirement that decoded ACE labels contain at least one non-ASCII code point. Originally unequal domain names can be regarded as equal, which can lead to blacklist bypassing, inconsistent URL parsing, and server-side request forgery in applications using the polyfill to canonicalise or compare hostnames. This issue is fixed in version 1.38.1.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.9 (LOW)
MEDIUM · 64/100
0.5% prob · 44th pct
1.38.1
2026-05-26
2026-09-10
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework-component symfony/monolog-bridge 7.1.1, bundle symfony/monolog-bundle 3.10.0 (1)

Direct (1)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
HIGH
HIGH 8.3
EPSS: 50%
Published: 2026-05-20
CVE-2026-45077
exact
composer:
symfony/monolog-bridge
7.1.1 direct
defined in: symfony/symfony-demo
CWE-502
Deserialization of Untrusted Data
CWE-668
Exposure of Resource to Wrong Sphere
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with unserialize(base64_decode($message)) without authentication, integrity checks, or an allowed_classes allowlist, allowing any reachable host to submit attacker-chosen serialized PHP payloads that can crash the listener and may trigger object-injection gadget effects. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (2)
  • CWE-502 — Deserialization of Untrusted Data
  • CWE-668 — Exposure of Resource to Wrong Sphere
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.3 (HIGH)
HIGH · 76.5/100
0.7% prob · 50th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework-component symfony/process 7.1.1, bundle symfonycasts/sass-bundle 0.3.0, bundle symfony/maker-bundle 1.59.1 (1)

Direct (1)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
HIGH
HIGH 8.4
EPSS: 36%
Published: 2024-11-05
CVE-2024-51736
exact
composer:
symfony/process
7.1.1 direct
defined in: symfony/symfony-demo
CWE-77
Command Injection
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. 7.1.7 nvdosvpackagist
Description
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking. This issue has been addressed in release versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Weaknesses (CWE) (1)
  • CWE-77 — Command Injection
Metadata
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
8.4 (HIGH)
HIGH · 74.5/100
0.4% prob · 36th pct
7.1.7
2024-11-05
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework-component symfony/routing 7.1.1, bundle doctrine/doctrine-bundle 2.12.0, bundle doctrine/doctrine-migrations-bundle 3.3.1, framework symfony/framework-bundle 7.1.1, bundle twig/extra-bundle 3.10.0, bundle dama/doctrine-test-bundle 8.2.0, bundle doctrine/doctrine-fixtures-bundle 3.6.1, bundle symfony/maker-bundle 1.59.1, framework-component symfony/web-profiler-bundle 7.1.1 (2)

Direct (2)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
MEDIUM
MEDIUM 5.1
EPSS: 29%
Published: 2026-05-26
CVE-2026-48784
exact
composer:
symfony/routing
7.1.1 direct
defined in: symfony/symfony-demo
CWE-172 CWE-601
URL Redirection to Untrusted Site (Open Redirect)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
Weaknesses (CWE) (2)
  • CWE-172 (unknown weakness)
  • CWE-601 — URL Redirection to Untrusted Site (Open Redirect)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.1 (MEDIUM)
MEDIUM · 46.5/100
0.3% prob · 29th pct
7.2.0
2026-05-26
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
LOW
MEDIUM 2.3
EPSS: 29%
Published: 2026-05-20
CVE-2026-45065
exact
composer:
symfony/routing
7.1.1 direct
defined in: symfony/symfony-demo
CWE-185
Incorrect Regular Expression
CWE-601
URL Redirection to Untrusted Site (Open Redirect)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle alternatives match as unanchored substrings, allowing a value such as //evil.com to satisfy a common locale requirement and generate a protocol-relative off-site URL. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (2)
  • CWE-185 — Incorrect Regular Expression
  • CWE-601 — URL Redirection to Untrusted Site (Open Redirect)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2.3 (MEDIUM)
LOW · 24.1/100
0.3% prob · 29th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework-component symfony/security-bundle 7.1.1 (1)

Direct (1)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
LOW
LOW 3.1
EPSS: 24%
Published: 2024-07-17
CVE-2024-50341
exact
composer:
symfony/security-bundle
7.1.1 direct
defined in: symfony/symfony-demo
CWE-287
Improper Authentication
symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. 7.1.3 nvdosvpackagist
Description
symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` defined on a firewall is not called when Login Programmaticaly with the `Security::login` method, leading to unwanted login. As of versions 6.4.10, 7.0.10 and 7.1.3 the `Security::login` method now ensure to call the configured `user_checker`. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Weaknesses (CWE) (1)
  • CWE-287 — Improper Authentication
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
3.1 (LOW)
LOW · 29.7/100
0.3% prob · 24th pct
7.1.3
2024-07-17
2024-11-07
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework-component symfony/security-bundle 7.1.1, framework-component symfony/security-http 7.1.1 (4)

Direct (4)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
HIGH
HIGH 8.7
EPSS: 47%
Published: 2026-05-26
CVE-2026-48489
exact
composer:
symfony/security-http
7.1.1 direct
defined in: symfony/symfony-demo
CWE-863
Incorrect Authorization
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler honored the request-supplied _failure_path parameter when failure_forward: true was enabled, allowing an unauthenticated failing login request to dispatch a subrequest to access_control-protected GET routes that skipped firewall listeners. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
Weaknesses (CWE) (1)
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (HIGH)
HIGH · 79/100
0.6% prob · 47th pct
7.2.0
2026-05-26
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
HIGH
HIGH 9.1
EPSS: 31%
Published: 2026-05-20
CVE-2026-45063
exact
composer:
symfony/security-http
7.1.1 direct
defined in: symfony/symfony-demo
CWE-290
Authentication Bypass by Spoofing
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
  • CWE-290 — Authentication Bypass by Spoofing
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
9.1 (HIGH)
HIGH · 78.9/100
0.4% prob · 31th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
HIGH 7.5
EPSS: 48%
Published: 2024-11-13
CVE-2024-51996
exact
composer:
symfony/security-http
7.1.1 direct
defined in: symfony/symfony-demo
CWE-287
Improper Authentication
CWE-289
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. 7.1.8 nvdosvpackagist
Description
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8.
Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
7.5 (HIGH)
MEDIUM · 69.7/100
0.6% prob · 48th pct
7.1.8
2024-11-13
2024-11-15
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 7.6
EPSS: 41%
Published: 2026-05-20
CVE-2026-45074
exact
composer:
symfony/security-http
7.1.1 direct
defined in: symfony/symfony-demo
CWE-290
Authentication Bypass by Spoofing
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled Host header when framework.trusted_hosts is not configured; an attacker controlling another application registered with the same CAS server can replay a victim ticket against the Symfony application and authenticate as the victim. This issue is fixed in versions 7.4.12 and 8.0.12.
Weaknesses (CWE) (1)
  • CWE-290 — Authentication Bypass by Spoofing
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.6 (MEDIUM)
MEDIUM · 69/100
0.5% prob · 41th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (2)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

bundle symfony/stimulus-bundle 2.17.0, framework-component symfony/twig-bridge 7.1.1, framework-component symfony/twig-bundle 7.1.1, bundle twig/extra-bundle 3.10.0, framework-component symfony/debug-bundle 7.1.1, framework-component symfony/web-profiler-bundle 7.1.1 (18)

Indirect (18)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
HIGH
HIGH 8.8
EPSS: 54%
Published: 2026-05-20
CVE-2026-24425
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-693
Protection Mechanism Failure
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and red… 3.26.0 nvdosvpackagist
Description
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.
Weaknesses (CWE) (1)
  • CWE-693 — Protection Mechanism Failure
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.8 (HIGH)
HIGH · 81.2/100
0.8% prob · 54th pct
3.26.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (2)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
HIGH
CRITICAL 8.7
EPSS: 51%
Published: 2026-05-20
CVE-2026-46633
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-94
Code Injection
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to termin… 3.26.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (CRITICAL)
HIGH · 79.9/100
0.7% prob · 51th pct
3.26.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
HIGH
MEDIUM 8.5
EPSS: 57%
Published: 2024-09-09
CVE-2024-45411
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-693
Protection Mechanism Failure
Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0. 3.11.0 nvdosvpackagist
Description
Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.
Weaknesses (CWE) (1)
  • CWE-693 — Protection Mechanism Failure
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
8.5 (MEDIUM)
HIGH · 79.3/100
0.8% prob · 57th pct
3.11.0
2024-09-09
2024-10-10
exact
nvd+osv+packagist
Affected CPE configurations (3)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
HIGH
HIGH 8.7
EPSS: 30%
Published: 2026-05-27
CVE-2026-46636
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-1336 Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. 3.27.0 nvdpackagist
Description
Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0.
Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (HIGH)
HIGH · 75.5/100
0.4% prob · 30th pct
3.27.0
2026-05-27
2026-09-08
exact
nvd+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
HIGH
MEDIUM 7.7
EPSS: 48%
Published: 2026-05-20
CVE-2026-46634
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-693
Protection Mechanism Failure
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sa… 3.26.0 nvdosvpackagist
Description
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and include to render an inner template without security policy enforcement. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
  • CWE-693 — Protection Mechanism Failure
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.7 (MEDIUM)
HIGH · 71.2/100
0.6% prob · 48th pct
3.26.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
HIGH 7.1
EPSS: 45%
Published: 2026-05-20
CVE-2026-46627
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-400
Uncontrolled Resource Consumption (DoS)
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustio… 3.26.0 nvdpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.
Weaknesses (CWE) (1)
  • CWE-400 — Uncontrolled Resource Consumption (DoS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.1 (HIGH)
MEDIUM · 65.7/100
0.5% prob · 45th pct
3.26.0
2026-05-20
2026-07-16
exact
nvd+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 7.1
EPSS: 36%
Published: 2026-05-27
CVE-2026-48806
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-693
Protection Mechanism Failure
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxE… 3.27.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0.
Weaknesses (CWE) (2)
  • CWE-693 — Protection Mechanism Failure
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.1 (MEDIUM)
MEDIUM · 64/100
0.4% prob · 36th pct
3.27.0
2026-05-27
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
HIGH 7.1
EPSS: 34%
Published: 2026-05-20
CVE-2026-47732
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invo… 3.26.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.1 (HIGH)
MEDIUM · 63.6/100
0.4% prob · 34th pct
3.26.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 7.1
EPSS: 31%
Published: 2026-05-27
CVE-2026-48807
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-693
Protection Mechanism Failure
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringab… 3.27.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.
Weaknesses (CWE) (2)
  • CWE-693 — Protection Mechanism Failure
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.1 (MEDIUM)
MEDIUM · 62.9/100
0.4% prob · 31th pct
3.27.0
2026-05-27
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 6.0
EPSS: 40%
Published: 2026-05-20
CVE-2026-46638
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-693
Protection Mechanism Failure
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, a… 3.26.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, and functions that should have been denied by SecurityPolicy::checkSecurity(). This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
  • CWE-693 — Protection Mechanism Failure
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.0 (MEDIUM)
MEDIUM · 56/100
0.5% prob · 40th pct
3.26.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
MEDIUM 6.0
EPSS: 35%
Published: 2026-05-27
CVE-2026-48808
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-693
Protection Mechanism Failure
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are… 3.27.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0.
Weaknesses (CWE) (2)
  • CWE-693 — Protection Mechanism Failure
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.0 (MEDIUM)
MEDIUM · 54.9/100
0.4% prob · 35th pct
3.27.0
2026-05-27
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
HIGH 6.0
EPSS: 30%
Published: 2026-07-01
CVE-2026-49981
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-693
Protection Mechanism Failure
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allow… — nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.
Weaknesses (CWE) (2)
  • CWE-693 — Protection Mechanism Failure
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.0 (HIGH)
MEDIUM · 54/100
0.4% prob · 30th pct
2026-07-01
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
LOW 5.3
EPSS: 41%
Published: 2026-05-27
CVE-2026-48805
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-693
Protection Mechanism Failure
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such … 3.27.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arrow_in_sandbox() to bypass sandbox callable restrictions. This issue is fixed in version 3.27.0.
Weaknesses (CWE) (1)
  • CWE-693 — Protection Mechanism Failure
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (LOW)
MEDIUM · 50.6/100
0.5% prob · 41th pct
3.27.0
2026-05-27
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
LOW 5.3
EPSS: 26%
Published: 2026-05-20
CVE-2026-46635
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-863
Incorrect Authorization
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAll… 3.26.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAllowed(), allowing an untrusted template author with column in allowedFilters to read properties that are not in the sandbox allowlist. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
  • CWE-863 — Incorrect Authorization
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3 (LOW)
MEDIUM · 47.7/100
0.3% prob · 26th pct
3.26.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
LOW 5.1
EPSS: 22%
Published: 2026-05-20
CVE-2026-46628
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-116
Improper Encoding or Escaping of Output
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. 3.26.0 nvdosvpackagist
Description
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
  • CWE-116 — Improper Encoding or Escaping of Output
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.1 (LOW)
MEDIUM · 45.3/100
0.3% prob · 22th pct
3.26.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
MEDIUM
LOW 5.1
EPSS: 22%
Published: 2026-05-20
CVE-2026-47730
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-79
Cross-site Scripting (XSS)
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to … 3.26.0 nvdosvpackagist
Description
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.
Weaknesses (CWE) (1)
  • CWE-79 — Cross-site Scripting (XSS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.1 (LOW)
MEDIUM · 45.3/100
0.3% prob · 22th pct
3.26.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (1)
  • cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
LOW
LOW 2.2
EPSS: 37%
Published: 2024-11-06
CVE-2024-51754
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-668
Exposure of Resource to Wrong Sphere
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments t… 3.11.2 nvdosvpackagist
Description
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments to a function or a filter for instance). This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue.
Weaknesses (CWE) (1)
  • CWE-668 — Exposure of Resource to Wrong Sphere
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
2.2 (LOW)
LOW · 25.1/100
0.4% prob · 37th pct
3.11.2
2024-11-06
2025-05-29
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
LOW
LOW 2.2
EPSS: 37%
Published: 2024-11-06
CVE-2024-51755
exact
composer:
twig/twig
3.10.3 direct
defined in: symfony/symfony-demo
CWE-668
Exposure of Resource to Wrong Sphere
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. 3.11.2 nvdosvpackagist
Description
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the security check. This is a BC break. This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue.
Weaknesses (CWE) (1)
  • CWE-668 — Exposure of Resource to Wrong Sphere
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
2.2 (LOW)
LOW · 25/100
0.4% prob · 37th pct
3.11.2
2024-11-06
2024-11-12
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework-component symfony/validator 7.1.1 (1)

Direct (1)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
LOW
LOW 3.1
EPSS: 39%
Published: 2024-08-30
CVE-2024-50343
exact
composer:
symfony/validator
7.1.1 direct
defined in: symfony/symfony-demo
CWE-20
Improper Input Validation
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. 7.1.4 nvdosvpackagist
Description
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. Symfony as of versions 5.4.43, 6.4.11, and 7.1.4 now uses the `D` regex modifier to match the entire input. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Weaknesses (CWE) (1)
  • CWE-20 — Improper Input Validation
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
3.1 (LOW)
LOW · 32.6/100
0.5% prob · 39th pct
7.1.4
2024-08-30
2025-11-03
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

framework-component symfony/yaml 7.1.1 (3)

Direct (3)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
HIGH
LOW 8.7
EPSS: 51%
Published: 2026-05-20
CVE-2026-45304
exact
composer:
symfony/yaml
7.1.1 direct
defined in: symfony/symfony-demo
CWE-776
XML Entity Expansion (XEE / Billion Laughs)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small untrusted YAML input to expand into a multi-gigabyte structure and exhaust memory. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
  • CWE-776 — XML Entity Expansion (XEE / Billion Laughs)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (LOW)
HIGH · 79.8/100
0.7% prob · 51th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
HIGH
LOW 8.7
EPSS: 51%
Published: 2026-05-20
CVE-2026-45305
exact
composer:
symfony/yaml
7.1.1 direct
defined in: symfony/symfony-demo
CWE-1333
Inefficient Regular Expression Complexity (ReDoS)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbitrarily long time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
  • CWE-1333 — Inefficient Regular Expression Complexity (ReDoS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (LOW)
HIGH · 79.8/100
0.7% prob · 51th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock
HIGH
LOW 8.2
EPSS: 49%
Published: 2026-05-20
CVE-2026-45133
exact
composer:
symfony/yaml
7.1.1 direct
defined in: symfony/symfony-demo
CWE-674
Uncontrolled Recursion
CWE-776
XML Entity Expansion (XEE / Billion Laughs)
+1
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parsers to recurse without a depth limit. A crafted document exhausts the PHP stack and crashes the worker. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (3)
  • CWE-674 — Uncontrolled Recursion
  • CWE-776 — XML Entity Expansion (XEE / Billion Laughs)
  • CWE-1333 — Inefficient Regular Expression Complexity (ReDoS)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.2 (LOW)
HIGH · 75.4/100
0.6% prob · 49th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

Dev dependencies (8)

drupal · drupal (4)

core Drupal 8.5.0 (4)

Indirect (4)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
HIGH
LOW 8.7
EPSS: 46%
Published: 2026-05-20
CVE-2026-45071
exact
composer:
symfony/dom-crawler
3.4.4 direct dev
defined in: drupal/drupal
CWE-611
XML External Entity (XXE)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 4.0.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing attacker-supplied XML to expand file:// entities such as local files. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
  • CWE-611 — XML External Entity (XXE)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (LOW)
HIGH · 78.8/100
0.6% prob · 46th pct
4.0.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
HIGH
HIGH 7.1
EPSS: 82%
Published: 2019-04-16
CVE-2019-10912
exact
composer:
symfony/phpunit-bridge
3.4.4 direct dev
defined in: drupal/drupal
CWE-502
Deserialization of Untrusted Data
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. 3.4.26 nvdosvpackagist
Description
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge.
Weaknesses (CWE) (1)
  • CWE-502 — Deserialization of Untrusted Data
Metadata
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
7.1 (HIGH)
HIGH · 73.2/100
2.3% prob · 82th pct
3.4.26
2019-04-16
2024-03-13
exact
nvd+osv+packagist
External links (14)
Security advisory1 link
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
HIGH 7.3
EPSS: 52%
Published: 2026-08-05
CVE-2026-67434
exact
composer:
squizlabs/php_codesniffer
2.8.1 direct dev
defined in: drupal/drupal
CWE-78
OS Command Injection
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. 3.13.6 nvdosvpackagist
Description
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as " and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2.
Weaknesses (CWE) (1)
  • CWE-78 — OS Command Injection
Metadata
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.3 (HIGH)
MEDIUM · 68.8/100
0.7% prob · 52th pct
3.13.6
2026-08-05
2026-08-06
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
drupal/composer.lock
MEDIUM
HIGH 7.8
EPSS: 29%
Published: 2026-01-27
CVE-2026-24765
exact
composer:
phpunit/phpunit
4.8.36 direct dev
defined in: drupal/drupal
CWE-502
Deserialization of Untrusted Data
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. 8.5.52 nvdosvpackagist
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Weaknesses (CWE) (1)
  • CWE-502 — Deserialization of Untrusted Data
Metadata
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 (HIGH)
MEDIUM · 68.3/100
0.4% prob · 29th pct
8.5.52
2026-01-27
2026-05-05
exact
nvd+osv+packagist
Affected CPE configurations (6)
  • cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
  • cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
  • cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
  • cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
  • cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
drupal/composer.lock

laravel · bookstack (3)

framework laravel/framework 10.48.22 (3)

Indirect (3)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
HIGH
LOW 8.7
EPSS: 46%
Published: 2026-05-20
CVE-2026-45071
exact
composer:
symfony/dom-crawler
6.4.12 direct dev
defined in: bookstackapp/bookstack
CWE-611
XML External Entity (XXE)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 6.4.40 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing attacker-supplied XML to expand file:// entities such as local files. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
  • CWE-611 — XML External Entity (XXE)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (LOW)
HIGH · 78.8/100
0.6% prob · 46th pct
6.4.40
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 7.3
EPSS: 52%
Published: 2026-08-05
CVE-2026-67434
exact
composer:
squizlabs/php_codesniffer
3.10.3 direct dev
defined in: bookstackapp/bookstack
CWE-78
OS Command Injection
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. 3.13.6 nvdosvpackagist
Description
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as " and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2.
Weaknesses (CWE) (1)
  • CWE-78 — OS Command Injection
Metadata
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
7.3 (HIGH)
MEDIUM · 68.8/100
0.7% prob · 52th pct
3.13.6
2026-08-05
2026-08-06
exact
nvd+osv+packagist
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock
MEDIUM
HIGH 7.8
EPSS: 29%
Published: 2026-01-27
CVE-2026-24765
exact
composer:
phpunit/phpunit
10.5.35 direct dev
defined in: bookstackapp/bookstack
CWE-502
Deserialization of Untrusted Data
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. 10.5.62 nvdosvpackagist
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Weaknesses (CWE) (1)
  • CWE-502 — Deserialization of Untrusted Data
Metadata
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 (HIGH)
MEDIUM · 68.3/100
0.4% prob · 29th pct
10.5.62
2026-01-27
2026-05-05
exact
nvd+osv+packagist
Affected CPE configurations (6)
  • cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
  • cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
  • cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
  • cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
  • cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock

symfony · symfony-demo (1)

framework-component symfony/dom-crawler 7.1.1, framework-component symfony/browser-kit 7.1.1 (1)

Direct (1)

Priority / severityCVE IDDependencyCWEDescriptionFix VersionSource
HIGH
LOW 8.7
EPSS: 46%
Published: 2026-05-20
CVE-2026-45071
exact
composer:
symfony/dom-crawler
7.1.1 direct dev
defined in: symfony/symfony-demo
CWE-611
XML External Entity (XXE)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. 7.2.0 nvdosvpackagist
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing attacker-supplied XML to expand file:// entities such as local files. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Weaknesses (CWE) (1)
  • CWE-611 — XML External Entity (XXE)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7 (LOW)
HIGH · 78.8/100
0.6% prob · 46th pct
7.2.0
2026-05-20
2026-09-10
exact
nvd+osv+packagist
Affected CPE configurations (4)
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock

1.2 Vendored JS vulns — retire.js (44)

SevLibraryFilesCVECWEVulns
HIGH tinyMCE
4.9.11
wp/wp-includes/js/tinymce/tinymce.min.js
wp/wp-includes/js/tinymce/wp-tinymce.js
CDATA parsing and sanitization has been improved to address a cross-site scripting (XSS) vulnerabili… media embed content not processing safely in some cases. content in an iframe element parsing as DOM elements instead of text content. Regex denial of service vulnerability in codesample plugin CVE-2024-21911 URLs are not correctly filtered in some cases. CVE-2024-21908 CVE-2024-21910 CVE-2022-23494 CVE-2023-45819 CVE-2023-45818 CVE-2023-48219 CVE-2026-47761 CVE-2024-38356 CVE-2024-38357 CVE-2026-47759 CVE-2026-47762 CVE-2024-29203 CVE-2024-29881 CWE-79 19 vulns
SevCVE / GHSAFixed inSummary
MEDIUM CDATA parsing and sanitization has been improved to address a cross-site scripting (XSS) vulnerabili… 5.1.6 CDATA parsing and sanitization has been improved to address a cross-site scripting (XSS) vulnerability.
LOW media embed content not processing safely in some cases. 5.2.2 media embed content not processing safely in some cases.
LOW content in an iframe element parsing as DOM elements instead of text content. 5.4.0 content in an iframe element parsing as DOM elements instead of text content.
LOW Regex denial of service vulnerability in codesample plugin 5.6.0 Regex denial of service vulnerability in codesample plugin
MEDIUM CVE-2024-21911 5.6.0 TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability.
MEDIUM URLs are not correctly filtered in some cases. 5.7.1 URLs are not correctly filtered in some cases.
MEDIUM CVE-2024-21908 5.9.0 TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability.
MEDIUM CVE-2024-21910 5.10.0 TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability.
MEDIUM CVE-2022-23494 5.10.7 tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in the alert and confirm dialogs when these dialogs were provided with malicious HTML content.
MEDIUM CVE-2023-45819 5.10.8 TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notification Manager API.
MEDIUM CVE-2023-45818 5.10.8 TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo functionality.
MEDIUM CVE-2023-48219 5.10.9 TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins.
HIGH CVE-2026-47761 5.10.10 TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin.
MEDIUM CVE-2024-38356 5.11.0 TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code.
MEDIUM CVE-2024-38357 5.11.0 TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code.
HIGH CVE-2026-47759 5.11.1 TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style).
HIGH CVE-2026-47762 5.11.1 TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments.
MEDIUM CVE-2024-29203 6.8.1 TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containing malicious code to execute when inserted into the editor.
MEDIUM CVE-2024-29881 7.0.0 TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code.
HIGH ua-parser-js
0.7.7
wp/wp-includes/js/plupload/moxie.js
CVE-2020-7733 CVE-2020-7793 CWE-400 2 vulns
SevCVE / GHSAFixed inSummary
HIGH CVE-2020-7733 0.7.22 The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
HIGH CVE-2020-7793 0.7.23 The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
HIGH underscore.js
1.13.6
wp/wp-includes/js/underscore.js
CVE-2026-27601 CWE-770 1 vuln
SevCVE / GHSAFixed inSummary
HIGH CVE-2026-27601 1.13.8 Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit.
MEDIUM plupload
2.1.9
wp/wp-includes/js/plupload/plupload.js
Fixed security vulnerability by adding die calls to all php files to prevent them from being execute… Fixed a potential security issue with not entity encoding the file names in the html in the queue/ui… CVE-2021-23562 CWE-434 3 vulns
SevCVE / GHSAFixed inSummary
MEDIUM Fixed security vulnerability by adding die calls to all php files to prevent them from being execute… 2.3.7 Fixed security vulnerability by adding die calls to all php files to prevent them from being executed unless modified.
MEDIUM Fixed a potential security issue with not entity encoding the file names in the html in the queue/ui… 2.3.8 Fixed a potential security issue with not entity encoding the file names in the html in the queue/ui widgets.
MEDIUM CVE-2021-23562 2.3.9 This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.

2. Unmanaged / unversioned components (0 embedded, 0 native, 19 vendored JS, 146 crypto)

2.1 Unmanaged / vendored JavaScript (19)

Standalone JavaScript libraries committed into the tree (jQuery, Bootstrap, PDF.js, …) that no package manager governs — unknown provenance, integrity and patch story, identified by signature (retire.js). This is a cyber-hygiene inventory: even a non-vulnerable copy is unmanaged third-party code. 5 of 19 carry known vulnerabilities (detailed in chapter 2).
LibraryVersionFileDetectionStatus
tinyMCE4.9.11wp/wp-includes/js/tinymce/tinymce.min.jsfilecontentreplace19 vulns · HIGH
tinyMCE4.9.11wp/wp-includes/js/tinymce/wp-tinymce.jsfilecontentreplace19 vulns · HIGH
ua-parser-js0.7.7wp/wp-includes/js/plupload/moxie.jsfilecontent2 vulns · HIGH
underscore.js1.13.6wp/wp-includes/js/underscore.jsfilecontent1 vuln · HIGH
plupload2.1.9wp/wp-includes/js/plupload/plupload.jsfilecontent3 vulns · MEDIUM
backbone.js1.5.0wp/wp-includes/js/backbone.jsfilecontentno known vuln
jquery3.7.1wp/wp-includes/js/jquery/jquery.jsfilecontentno known vuln
jquery3.7.1wp/wp-includes/js/jquery/jquery.min.jsfilecontentno known vuln
jquery-migrate3.4.1wp/wp-includes/js/jquery/jquery-migrate.jsfilecontentno known vuln
jquery-migrate3.4.1wp/wp-includes/js/jquery/jquery-migrate.min.jsfilecontentno known vuln
jquery-ui1.13.2wp/wp-includes/js/jquery/ui/core.jsfilecontentno known vuln
jquery-ui1.13.2wp/wp-includes/js/jquery/ui/core.min.jsfilecontentno known vuln
jquery-ui-autocomplete1.13.2wp/wp-includes/js/jquery/ui/autocomplete.jsfilecontentno known vuln
jquery-ui-autocomplete1.13.2wp/wp-includes/js/jquery/ui/autocomplete.min.jsfilecontentno known vuln
jquery-ui-dialog1.13.2wp/wp-includes/js/jquery/ui/dialog.jsfilecontentno known vuln
jquery-ui-dialog1.13.2wp/wp-includes/js/jquery/ui/dialog.min.jsfilecontentno known vuln
jquery-ui-tooltip1.13.2wp/wp-includes/js/jquery/ui/tooltip.jsfilecontentno known vuln
jquery-ui-tooltip1.13.2wp/wp-includes/js/jquery/ui/tooltip.min.jsfilecontentno known vuln
swfobject2.2wp/wp-includes/js/swfobject.jsfilecontentno known vuln

2.2 Certificates & key material (146)

Cryptographic material committed into the source tree — X.509 certificates, private & public keys (PEM / OpenSSH every algorithm / PuTTY / PGP / one-line SSH) and Java/PKCS#12 keystores. Each key is labelled private (a committed secret — critical) or public (inventory). Detected and parsed entirely offline (built-in X.509 parser; no network, no decryption). 0 private keys, 0 public keys, 13 expired certificates.
FileTypeAlgorithmDetailsFindingsSHA-256
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048EE Certification Centre Root CA ← EE Certification Centre Root CA
exp 2030-12-17 (1545d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 1024Thawte Server CA ← Thawte Server CA
exp 2020-12-31 (-2093d)
weak key EXPIRED weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 1024Thawte Premium Server CA ← Thawte Premium Server CA
exp 2020-12-31 (-2093d)
weak key EXPIRED weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 1024C=US ← C=US
exp 2028-08-01 (677d)
weak key weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 1024C=US ← C=US
exp 2028-08-01 (677d)
weak key weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048America Online Root Certification Authority 1 ← America Online Root Certification Authority 1
exp 2037-11-19 (4074d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096America Online Root Certification Authority 2 ← America Online Root Certification Authority 2
exp 2037-09-29 (4022d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 1024C=US ← C=US
exp 2028-08-02 (678d)
weak key weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048GlobalSign Root CA ← GlobalSign Root CA
exp 2028-01-28 (490d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048GlobalSign ← GlobalSign
exp 2021-12-15 (-1745d)
EXPIRED weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048VeriSign Class 3 Public Primary Certification Authority - G3 ← VeriSign Class 3 Public Primary Certification Authority - G3
exp 2036-07-16 (3583d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Entrust.net Certification Authority (2048) ← Entrust.net Certification Authority (2048)
exp 2029-07-24 (1033d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Baltimore CyberTrust Root ← Baltimore CyberTrust Root
exp 2025-05-12 (-500d)
EXPIRED weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Entrust Root Certification Authority ← Entrust Root Certification Authority
exp 2026-11-27 (64d)
expiring soon weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048GeoTrust Global CA ← GeoTrust Global CA
exp 2022-05-21 (-1588d)
EXPIRED weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096GeoTrust Universal CA ← GeoTrust Universal CA
exp 2029-03-04 (891d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096GeoTrust Universal CA 2 ← GeoTrust Universal CA 2
exp 2029-03-04 (891d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048AAA Certificate Services ← AAA Certificate Services
exp 2028-12-31 (829d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048QuoVadis Root Certification Authority ← QuoVadis Root Certification Authority
exp 2021-03-17 (-2017d)
EXPIRED weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096QuoVadis Root CA 2 ← QuoVadis Root CA 2
exp 2031-11-24 (1887d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096QuoVadis Root CA 3 ← QuoVadis Root CA 3
exp 2031-11-24 (1887d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048C=JP ← C=JP
exp 2023-09-30 (-1091d)
EXPIRED weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Sonera Class2 CA ← Sonera Class2 CA
exp 2021-04-06 (-1998d)
EXPIRED weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048XRamp Global Certification Authority ← XRamp Global Certification Authority
exp 2035-01-01 (3020d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048C=US ← C=US
exp 2034-06-29 (2835d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048C=US ← C=US
exp 2034-06-29 (2835d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096C=TW ← C=TW
exp 2032-12-05 (2263d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048DigiCert Assured ID Root CA ← DigiCert Assured ID Root CA
exp 2031-11-10 (1872d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048DigiCert Global Root CA ← DigiCert Global Root CA
exp 2031-11-10 (1872d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048DigiCert High Assurance EV Root CA ← DigiCert High Assurance EV Root CA
exp 2031-11-10 (1872d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096SwissSign Gold CA - G2 ← SwissSign Gold CA - G2
exp 2036-10-25 (3683d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096SwissSign Silver CA - G2 ← SwissSign Silver CA - G2
exp 2036-10-25 (3683d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048GeoTrust Primary Certification Authority ← GeoTrust Primary Certification Authority
exp 2036-07-16 (3583d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048thawte Primary Root CA ← thawte Primary Root CA
exp 2036-07-16 (3583d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048VeriSign Class 3 Public Primary Certification Authority - G5 ← VeriSign Class 3 Public Primary Certification Authority - G5
exp 2036-07-16 (3583d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048SecureTrust CA ← SecureTrust CA
exp 2029-12-31 (1194d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Secure Global CA ← Secure Global CA
exp 2029-12-31 (1194d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048COMODO Certification Authority ← COMODO Certification Authority
exp 2029-12-31 (1194d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Network Solutions Certificate Authority ← Network Solutions Certificate Authority
exp 2029-12-31 (1194d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048OISTE WISeKey Global Root GA CA ← OISTE WISeKey Global Root GA CA
exp 2037-12-11 (4095d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Certigna ← Certigna
exp 2027-06-29 (277d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Cybertrust Global Root ← Cybertrust Global Root
exp 2021-12-15 (-1745d)
EXPIRED weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096C=TW ← C=TW
exp 2034-12-20 (3008d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048C=RO ← C=RO
exp 2031-07-04 (1744d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Hongkong Post Root CA 1 ← Hongkong Post Root CA 1
exp 2023-05-15 (-1229d)
EXPIRED weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048SecureSign RootCA11 ← SecureSign RootCA11
exp 2029-04-08 (926d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Autoridad de Certificacion Firmaprofesional CIF A62634068 ← Autoridad de Certificacion Firmaprofesional CIF A62634068
exp 2030-12-31 (1558d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Chambers of Commerce Root - 2008 ← Chambers of Commerce Root - 2008
exp 2038-07-31 (4327d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Global Chambersign Root - 2008 ← Global Chambersign Root - 2008
exp 2038-07-31 (4327d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048AffirmTrust Networking ← AffirmTrust Networking
exp 2030-12-31 (1558d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Certum Trusted Network CA ← Certum Trusted Network CA
exp 2029-12-31 (1193d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048TWCA Root Certification Authority ← TWCA Root Certification Authority
exp 2030-12-31 (1558d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048EC-ACC ← EC-ACC
exp 2031-01-07 (1566d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Hellenic Academic and Research Institutions RootCA 2011 ← Hellenic Academic and Research Institutions RootCA 2011
exp 2031-12-01 (1893d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048C=GB ← C=GB
exp 2024-01-21 (-978d)
EXPIRED weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048EE Certification Centre Root CA ← EE Certification Centre Root CA
exp 2030-12-17 (1545d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096ACCVRAIZ1 ← ACCVRAIZ1
exp 2030-12-31 (1558d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096TeliaSonera Root CA v1 ← TeliaSonera Root CA v1
exp 2032-10-18 (2215d)
weak signature self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096E-Tugra Certification Authority ← E-Tugra Certification Authority
exp 2023-03-03 (-1302d)
EXPIRED self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Staat der Nederlanden EV Root CA ← Staat der Nederlanden EV Root CA
exp 2022-12-08 (-1387d)
EXPIRED self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1COMODO ECC Certification Authority ← COMODO ECC Certification Authority
exp 2038-01-18 (4134d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048GeoTrust Primary Certification Authority - G3 ← GeoTrust Primary Certification Authority - G3
exp 2037-12-01 (4086d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1thawte Primary Root CA - G2 ← thawte Primary Root CA - G2
exp 2038-01-18 (4134d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048thawte Primary Root CA - G3 ← thawte Primary Root CA - G3
exp 2037-12-01 (4086d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1GeoTrust Primary Certification Authority - G2 ← GeoTrust Primary Certification Authority - G2
exp 2038-01-18 (4134d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048VeriSign Universal Root Certification Authority ← VeriSign Universal Root Certification Authority
exp 2037-12-01 (4086d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1VeriSign Class 3 Public Primary Certification Authority - G4 ← VeriSign Class 3 Public Primary Certification Authority - G4
exp 2038-01-18 (4134d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048NetLock Arany (Class Gold) Főtanúsítvány ← NetLock Arany (Class Gold) Főtanúsítvány
exp 2028-12-06 (803d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Microsec e-Szigno Root CA 2009 ← Microsec e-Szigno Root CA 2009
exp 2029-12-30 (1192d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048GlobalSign ← GlobalSign
exp 2029-03-18 (905d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Izenpe.com ← Izenpe.com
exp 2037-12-13 (4097d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Go Daddy Root Certificate Authority - G2 ← Go Daddy Root Certificate Authority - G2
exp 2037-12-31 (4116d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Starfield Root Certificate Authority - G2 ← Starfield Root Certificate Authority - G2
exp 2037-12-31 (4116d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Starfield Services Root Certificate Authority - G2 ← Starfield Services Root Certificate Authority - G2
exp 2037-12-31 (4116d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048AffirmTrust Commercial ← AffirmTrust Commercial
exp 2030-12-31 (1558d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096AffirmTrust Premium ← AffirmTrust Premium
exp 2040-12-31 (5211d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1AffirmTrust Premium ECC ← AffirmTrust Premium ECC
exp 2040-12-31 (5211d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048C=JP ← C=JP
exp 2029-05-29 (977d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Actalis Authentication Root CA ← Actalis Authentication Root CA
exp 2030-09-22 (1458d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Buypass Class 2 Root CA ← Buypass Class 2 Root CA
exp 2040-10-26 (5145d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Buypass Class 3 Root CA ← Buypass Class 3 Root CA
exp 2040-10-26 (5145d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048T-TeleSec GlobalRoot Class 3 ← T-TeleSec GlobalRoot Class 3
exp 2033-10-01 (2564d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048D-TRUST Root Class 3 CA 2 2009 ← D-TRUST Root Class 3 CA 2 2009
exp 2029-11-05 (1137d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048D-TRUST Root Class 3 CA 2 EV 2009 ← D-TRUST Root Class 3 CA 2 EV 2009
exp 2029-11-05 (1137d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096CA Disig Root R2 ← CA Disig Root R2
exp 2042-07-19 (5776d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096TWCA Global Root CA ← TWCA Global Root CA
exp 2030-12-31 (1558d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048T-TeleSec GlobalRoot Class 2 ← T-TeleSec GlobalRoot Class 2
exp 2033-10-01 (2564d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Atos TrustedRoot 2011 ← Atos TrustedRoot 2011
exp 2030-12-31 (1559d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096QuoVadis Root CA 1 G3 ← QuoVadis Root CA 1 G3
exp 2042-01-12 (5589d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096QuoVadis Root CA 2 G3 ← QuoVadis Root CA 2 G3
exp 2042-01-12 (5589d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096QuoVadis Root CA 3 G3 ← QuoVadis Root CA 3 G3
exp 2042-01-12 (5589d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048DigiCert Assured ID Root G2 ← DigiCert Assured ID Root G2
exp 2038-01-15 (4130d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1DigiCert Assured ID Root G3 ← DigiCert Assured ID Root G3
exp 2038-01-15 (4130d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048DigiCert Global Root G2 ← DigiCert Global Root G2
exp 2038-01-15 (4130d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1DigiCert Global Root G3 ← DigiCert Global Root G3
exp 2038-01-15 (4130d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096DigiCert Trusted Root G4 ← DigiCert Trusted Root G4
exp 2038-01-15 (4130d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096COMODO RSA Certification Authority ← COMODO RSA Certification Authority
exp 2038-01-18 (4134d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096USERTrust RSA Certification Authority ← USERTrust RSA Certification Authority
exp 2038-01-18 (4134d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1USERTrust ECC Certification Authority ← USERTrust ECC Certification Authority
exp 2038-01-18 (4134d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC prime256v1GlobalSign ← GlobalSign
exp 2038-01-19 (4134d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1GlobalSign ← GlobalSign
exp 2038-01-19 (4134d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Staat der Nederlanden Root CA - G3 ← Staat der Nederlanden Root CA - G3
exp 2028-11-13 (781d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096IdenTrust Commercial Root CA 1 ← IdenTrust Commercial Root CA 1
exp 2034-01-16 (2671d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096IdenTrust Public Sector Root CA 1 ← IdenTrust Public Sector Root CA 1
exp 2034-01-16 (2671d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Entrust Root Certification Authority - G2 ← Entrust Root Certification Authority - G2
exp 2030-12-07 (1535d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1Entrust Root Certification Authority - EC1 ← Entrust Root Certification Authority - EC1
exp 2037-12-18 (4102d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096CFCA EV ROOT ← CFCA EV ROOT
exp 2029-12-31 (1193d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048OISTE WISeKey Global Root GB CA ← OISTE WISeKey Global Root GB CA
exp 2039-12-01 (4815d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048SZAFIR ROOT CA2 ← SZAFIR ROOT CA2
exp 2035-10-19 (3311d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Certum Trusted Network CA 2 ← Certum Trusted Network CA 2
exp 2046-10-06 (7316d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Hellenic Academic and Research Institutions RootCA 2015 ← Hellenic Academic and Research Institutions RootCA 2015
exp 2040-06-30 (5027d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1Hellenic Academic and Research Institutions ECC RootCA 2015 ← Hellenic Academic and Research Institutions ECC RootCA 2015
exp 2040-06-30 (5027d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096ISRG Root X1 ← ISRG Root X1
exp 2035-06-04 (3174d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096C=ES ← C=ES
exp 2030-01-01 (1194d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048Amazon Root CA 1 ← Amazon Root CA 1
exp 2038-01-17 (4132d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Amazon Root CA 2 ← Amazon Root CA 2
exp 2040-05-26 (4992d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC prime256v1Amazon Root CA 3 ← Amazon Root CA 3
exp 2040-05-26 (4992d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1Amazon Root CA 4 ← Amazon Root CA 4
exp 2040-05-26 (4992d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 1 ← TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 1
exp 2043-10-25 (6239d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096GDCA TrustAUTH R5 ROOT ← GDCA TrustAUTH R5 ROOT
exp 2040-12-31 (5211d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048TrustCor RootCert CA-1 ← TrustCor RootCert CA-1
exp 2029-12-31 (1194d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096TrustCor RootCert CA-2 ← TrustCor RootCert CA-2
exp 2034-12-31 (3020d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048TrustCor ECA-1 ← TrustCor ECA-1
exp 2029-12-31 (1194d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096SSL.com Root Certification Authority RSA ← SSL.com Root Certification Authority RSA
exp 2041-02-12 (5255d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1SSL.com Root Certification Authority ECC ← SSL.com Root Certification Authority ECC
exp 2041-02-12 (5255d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096SSL.com EV Root Certification Authority RSA R2 ← SSL.com EV Root Certification Authority RSA R2
exp 2042-05-30 (5727d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1SSL.com EV Root Certification Authority ECC ← SSL.com EV Root Certification Authority ECC
exp 2041-02-12 (5255d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096GlobalSign ← GlobalSign
exp 2034-12-10 (2998d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1OISTE WISeKey Global Root GC CA ← OISTE WISeKey Global Root GC CA
exp 2042-05-09 (5705d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096GTS Root R1 ← GTS Root R1
exp 2036-06-22 (3558d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096GTS Root R2 ← GTS Root R2
exp 2036-06-22 (3558d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1GTS Root R3 ← GTS Root R3
exp 2036-06-22 (3558d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1GTS Root R4 ← GTS Root R4
exp 2036-06-22 (3558d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096UCA Global G2 Root ← UCA Global G2 Root
exp 2040-12-31 (5211d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096UCA Extended Validation Root ← UCA Extended Validation Root
exp 2038-12-31 (4480d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Certigna Root CA ← Certigna Root CA
exp 2033-10-01 (2563d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048emSign Root CA - G1 ← emSign Root CA - G1
exp 2043-02-18 (5991d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1emSign ECC Root CA - G3 ← emSign ECC Root CA - G3
exp 2043-02-18 (5991d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 2048emSign Root CA - C1 ← emSign Root CA - C1
exp 2043-02-18 (5991d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1emSign ECC Root CA - C3 ← emSign ECC Root CA - C3
exp 2043-02-18 (5991d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Hongkong Post Root CA 3 ← Hongkong Post Root CA 3
exp 2042-06-03 (5730d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Entrust Root Certification Authority - G4 ← Entrust Root Certification Authority - G4
exp 2037-12-27 (4111d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC secp384r1Microsoft ECC Root Certificate Authority 2017 ← Microsoft ECC Root Certificate Authority 2017
exp 2042-07-18 (5776d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096Microsoft RSA Root Certificate Authority 2017 ← Microsoft RSA Root Certificate Authority 2017
exp 2042-07-18 (5776d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateEC prime256v1e-Szigno Root CA 2017 ← e-Szigno Root CA 2017
exp 2042-08-22 (5810d)
self-signed95b56bb9f0e8e470…
wp/wp-includes/certificates/ca-bundle.crtcertificateRSA 4096C=RO ← C=RO
exp 2042-02-06 (5613d)
self-signed95b56bb9f0e8e470…

3. Maintenance / EOL (5 EOL, 12 obsolete, 215 outdated)

3.1 End-of-Life frameworks (5)

Direct dependencies (5) — declared in your manifests (or, for Maven, inherited from a parent POM) — update these directly

ProductDependencyEOL dateLatestSourceNotes
Laravel composer:laravel/framework
10.48.22
defined in: bookstackapp/bookstack
2025-02-04 13.33.0 endoflife.date/laravel
matched via composer-framework = laravel/framework
The 10 branch ended at 10.50.3.
Symfony composer:symfony/browser-kit
3.4.4
+5 more components at cycle 3.4
defined in: drupal/drupal
2021-11-01 8.1.7 endoflife.date/symfony
matched via composer-framework = symfony/browser-kit
The 3.4 branch ended at 3.4.49.
Symfony composer:symfony/browser-kit
3.4.4
+3 more components at cycle 3.4
defined in: symfony/symfony-demo
2021-11-01 8.1.7 endoflife.date/symfony
matched via composer-framework = symfony/browser-kit
The 3.4 branch ended at 3.4.49.
Symfony composer:symfony/framework-bundle
7.1.1
+29 more components at cycle 7.1
defined in: symfony/symfony-demo
2025-01-31 8.1.7 endoflife.date/symfony
matched via composer-framework = symfony/framework-bundle
The 7.1 branch ended at 7.1.11.
PHP composer:php
8.1
defined in: bookstackapp/bookstack
2025-12-31 8.1.34 endoflife.date/php
matched via composer-platform = lock:platform-overrides
Constraint "8.1.0" (lock:platform-overrides) allows nothing newer than PHP 8.1 — latest 8.1.34.

3.2 Obsolete / deprecated (12)

SeverityObsoleteReplacementWhy
MEDIUM composer:doctrine/cache
2.2.0
defined in: bookstackapp/bookstack, drupal/drupal +1 more
— Package marked abandoned on Packagist
MEDIUM composer:doctrine/annotations
1.2.7
defined in: drupal/drupal
— Package marked abandoned on Packagist
MEDIUM composer:stack/builder
1.0.5
defined in: drupal/drupal
— Package marked abandoned on Packagist
MEDIUM composer:symfony/class-loader
3.4.4
defined in: drupal/drupal
— Package marked abandoned on Packagist
MEDIUM composer:symfony/debug
3.4.4
defined in: drupal/drupal
symfony/error-handler Package marked abandoned on Packagist
MEDIUM composer:zendframework/zend-diactoros
1.4.1
defined in: drupal/drupal
laminas/laminas-diactoros Package marked abandoned on Packagist
MEDIUM composer:zendframework/zend-escaper
2.5.2
defined in: drupal/drupal
laminas/laminas-escaper Package marked abandoned on Packagist
MEDIUM composer:zendframework/zend-feed
2.7.0
defined in: drupal/drupal
laminas/laminas-feed Package marked abandoned on Packagist
MEDIUM composer:zendframework/zend-stdlib
3.0.1
defined in: drupal/drupal
laminas/laminas-stdlib Package marked abandoned on Packagist
MEDIUM composer:behat/mink-goutte-driver
1.2.1
defined in: drupal/drupal
behat/mink-browserkit-driver Package marked abandoned on Packagist
MEDIUM composer:fabpot/goutte
3.2.1
defined in: drupal/drupal
symfony/browser-kit Package marked abandoned on Packagist
MEDIUM composer:phpunit/phpunit-mock-objects
2.3.8
defined in: drupal/drupal
— Package marked abandoned on Packagist

3.3 Outdated (215)

JumpDependencyCurrentLatestReleased
+1 major composer:asm89/stack-cors
defined in: drupal/drupal
1.2.0 2.4.0
+1 major composer:behat/mink-browserkit-driver
defined in: drupal/drupal
1.3.2 2.3.0
+1 major composer:brick/math
defined in: bookstackapp/bookstack
0.12.1 1.0.0
+1 major composer:carbonphp/carbon-doctrine-types
defined in: bookstackapp/bookstack
2.1.0 3.2.1
+1 major composer:composer/installers
defined in: drupal/drupal
1.5.0 2.3.0
+2 major composer:composer/semver
defined in: drupal/drupal, symfony/symfony-demo
1.4.2 3.4.4
+2 major composer:doctrine/collections
defined in: drupal/drupal, symfony/symfony-demo
1.3.0 3.1.0
+1 major composer:doctrine/common
defined in: drupal/drupal
2.6.2 3.5.0
+1 major composer:doctrine/data-fixtures
defined in: symfony/symfony-demo
1.7.0 2.2.1
+1 major composer:doctrine/dbal
defined in: bookstackapp/bookstack, symfony/symfony-demo
3.9.1 4.4.4
+1 major composer:doctrine/doctrine-bundle
defined in: symfony/symfony-demo
2.12.0 3.3.2
+1 major composer:doctrine/doctrine-fixtures-bundle
defined in: symfony/symfony-demo
3.6.1 4.3.1
+1 major composer:doctrine/doctrine-migrations-bundle
defined in: symfony/symfony-demo
3.3.1 4.0.1
+1 major composer:doctrine/persistence
defined in: symfony/symfony-demo
3.3.2 4.2.0
+1 major composer:drupal/coder
defined in: drupal/drupal
8.2.12 9.0.1
+1 major composer:easyrdf/easyrdf
defined in: drupal/drupal
0.9.1 1.1.1
+1 major composer:firebase/php-jwt
defined in: bookstackapp/bookstack
6.10.1 7.2.0
+1 major composer:guzzlehttp/guzzle
defined in: bookstackapp/bookstack, drupal/drupal
7.9.2 8.2.0
+1 major composer:guzzlehttp/promises
defined in: bookstackapp/bookstack, drupal/drupal
2.0.3 3.0.2
+1 major composer:guzzlehttp/psr7
defined in: bookstackapp/bookstack, drupal/drupal
2.7.0 3.1.0
+1 major composer:guzzlehttp/uri-template
defined in: bookstackapp/bookstack
1.0.3 2.0.1
+1 major composer:hamcrest/hamcrest-php
defined in: bookstackapp/bookstack
2.0.1 3.0.0
+1 major composer:intervention/gif
defined in: bookstackapp/bookstack
4.2.0 5.0.1
+1 major composer:intervention/image
defined in: bookstackapp/bookstack
3.8.0 4.3.2
+1 major composer:larastan/larastan
defined in: bookstackapp/bookstack
2.9.8 3.12.2
+1 major composer:laravel/serializable-closure
defined in: bookstackapp/bookstack
1.3.5 2.1.0
+1 major composer:laravel/tinker
defined in: bookstackapp/bookstack
2.10.0 3.0.2
+1 major composer:nesbot/carbon
defined in: bookstackapp/bookstack
2.72.5 3.14.0
+1 major composer:nunomaduro/collision
defined in: bookstackapp/bookstack
7.10.0 8.9.5
+1 major composer:nunomaduro/termwind
defined in: bookstackapp/bookstack
1.15.1 2.4.0
+4 major composer:phpdocumentor/reflection-docblock
defined in: drupal/drupal
2.0.4 6.0.3
+1 major composer:phpmyadmin/sql-parser
defined in: bookstackapp/bookstack
5.10.0 6.0.0
+1 major composer:phpseclib/phpseclib
defined in: bookstackapp/bookstack
3.0.42 4.0.1
+1 major composer:phpstan/phpstan
defined in: bookstackapp/bookstack, symfony/symfony-demo
1.12.5 2.2.14
+1 major composer:phpstan/phpstan-doctrine
defined in: symfony/symfony-demo
1.4.1 2.0.28
+1 major composer:phpstan/phpstan-symfony
defined in: symfony/symfony-demo
1.4.3 2.0.20
+4 major composer:phpunit/php-code-coverage
defined in: bookstackapp/bookstack, drupal/drupal
10.1.16 14.3.3
+3 major composer:phpunit/php-file-iterator
defined in: bookstackapp/bookstack, drupal/drupal
4.1.0 7.0.2
+3 major composer:phpunit/php-invoker
defined in: bookstackapp/bookstack
4.0.0 7.0.0
+3 major composer:phpunit/php-text-template
defined in: bookstackapp/bookstack, drupal/drupal
3.0.1 6.0.0
+3 major composer:phpunit/php-timer
defined in: bookstackapp/bookstack, drupal/drupal
6.0.0 9.0.0
+3 major composer:phpunit/php-token-stream
defined in: drupal/drupal
1.4.11 4.0.4
+3 major composer:phpunit/phpunit
defined in: bookstackapp/bookstack, drupal/drupal
10.5.35 13.3.4
+1 major composer:pragmarx/google2fa
defined in: bookstackapp/bookstack
8.0.3 9.1.0
+1 major composer:predis/predis
defined in: bookstackapp/bookstack
2.2.2 3.6.1
+1 major composer:robrichards/xmlseclibs
defined in: bookstackapp/bookstack
3.1.1 4.0.0
+1 major composer:sabberworm/php-css-parser
defined in: bookstackapp/bookstack
8.6.0 9.5.0
+3 major composer:sebastian/cli-parser
defined in: bookstackapp/bookstack
2.0.1 5.0.1
+1 major composer:sebastian/code-unit
defined in: bookstackapp/bookstack
2.0.0 3.0.3
+1 major composer:sebastian/code-unit-reverse-lookup
defined in: bookstackapp/bookstack
3.0.0 4.0.1
+3 major composer:sebastian/comparator
defined in: bookstackapp/bookstack, drupal/drupal
5.0.2 8.4.0
+3 major composer:sebastian/complexity
defined in: bookstackapp/bookstack
3.2.0 6.0.0
+4 major composer:sebastian/diff
defined in: bookstackapp/bookstack, drupal/drupal
5.1.1 9.0.1
+3 major composer:sebastian/environment
defined in: bookstackapp/bookstack, drupal/drupal
6.1.0 9.3.2
+3 major composer:sebastian/exporter
defined in: bookstackapp/bookstack, drupal/drupal
5.1.2 8.2.1
+3 major composer:sebastian/global-state
defined in: bookstackapp/bookstack, drupal/drupal
6.0.2 9.0.1
+3 major composer:sebastian/lines-of-code
defined in: bookstackapp/bookstack
2.0.2 5.0.2
+3 major composer:sebastian/object-enumerator
defined in: bookstackapp/bookstack
5.0.0 8.1.0
+3 major composer:sebastian/object-reflector
defined in: bookstackapp/bookstack
3.0.0 6.1.0
+3 major composer:sebastian/recursion-context
defined in: bookstackapp/bookstack, drupal/drupal
5.0.0 8.0.1
+3 major composer:sebastian/type
defined in: bookstackapp/bookstack
4.0.0 7.0.2
+3 major composer:sebastian/version
defined in: bookstackapp/bookstack, drupal/drupal
4.0.1 7.0.0
+1 major composer:squizlabs/php_codesniffer
defined in: bookstackapp/bookstack, drupal/drupal
3.10.3 4.0.4
+1 major composer:ssddanbrown/htmldiff
defined in: bookstackapp/bookstack
1.0.3 2.0.0
+2 major composer:symfony-cmf/routing
defined in: drupal/drupal
1.4.1 3.0.5
+1 major composer:symfony/asset
defined in: symfony/symfony-demo
7.1.1 8.1.0
+1 major composer:symfony/asset-mapper
defined in: symfony/symfony-demo
7.1.1 8.1.7
+1 major composer:symfony/cache
defined in: symfony/symfony-demo
7.1.1 8.1.7
+1 major composer:symfony/clock
defined in: symfony/symfony-demo
7.1.1 8.1.0
+1 major composer:symfony/config
defined in: symfony/symfony-demo
7.1.1 8.1.5
+2 major composer:symfony/console
defined in: bookstackapp/bookstack, drupal/drupal +1 more
6.4.12 8.1.7
+2 major composer:symfony/css-selector
defined in: bookstackapp/bookstack, drupal/drupal +1 more
6.4.8 8.1.6
+1 major composer:symfony/debug-bundle
defined in: symfony/symfony-demo
7.1.1 8.1.0
+5 major composer:symfony/dependency-injection
defined in: drupal/drupal, symfony/symfony-demo
3.4.4 8.1.7
+1 major composer:symfony/doctrine-bridge
defined in: symfony/symfony-demo
7.1.1 8.1.7
+2 major composer:symfony/dom-crawler
defined in: bookstackapp/bookstack, drupal/drupal +1 more
6.4.12 8.1.5
+1 major composer:symfony/dotenv
defined in: symfony/symfony-demo
7.1.1 8.1.6
+2 major composer:symfony/error-handler
defined in: bookstackapp/bookstack, symfony/symfony-demo
6.4.10 8.1.5
+2 major composer:symfony/event-dispatcher
defined in: bookstackapp/bookstack, drupal/drupal +1 more
6.4.8 8.1.5
+1 major composer:symfony/expression-language
defined in: symfony/symfony-demo
7.1.1 8.1.6
+1 major composer:symfony/filesystem
defined in: symfony/symfony-demo
7.1.1 8.1.6
+2 major composer:symfony/finder
defined in: bookstackapp/bookstack, symfony/symfony-demo
6.4.11 8.1.7
+1 major composer:symfony/form
defined in: symfony/symfony-demo
7.1.1 8.1.7
+1 major composer:symfony/html-sanitizer
defined in: symfony/symfony-demo
7.1.1 8.1.7
+1 major composer:symfony/http-client
defined in: symfony/symfony-demo
7.1.1 8.1.7
+2 major composer:symfony/http-foundation
defined in: bookstackapp/bookstack, drupal/drupal +1 more
6.4.12 8.1.7
+2 major composer:symfony/http-kernel
defined in: bookstackapp/bookstack, drupal/drupal +1 more
6.4.12 8.1.7
+1 major composer:symfony/intl
defined in: symfony/symfony-demo
7.1.1 8.1.5
+1 major composer:symfony/mailer
defined in: symfony/symfony-demo
7.1.1 8.1.7
+2 major composer:symfony/mime
defined in: bookstackapp/bookstack, symfony/symfony-demo
6.4.12 8.1.7
+1 major composer:symfony/monolog-bridge
defined in: symfony/symfony-demo
7.1.1 8.1.6
+1 major composer:symfony/monolog-bundle
defined in: symfony/symfony-demo
3.10.0 4.1.0
+1 major composer:symfony/options-resolver
defined in: symfony/symfony-demo
7.1.1 8.1.0
+1 major composer:symfony/password-hasher
defined in: symfony/symfony-demo
7.1.1 8.1.0
+5 major composer:symfony/phpunit-bridge
defined in: drupal/drupal, symfony/symfony-demo
3.4.4 8.1.6
+2 major composer:symfony/process
defined in: bookstackapp/bookstack, drupal/drupal +1 more
6.4.12 8.1.7
+1 major composer:symfony/property-access
defined in: symfony/symfony-demo
7.1.1 8.1.4
+1 major composer:symfony/property-info
defined in: symfony/symfony-demo
7.1.1 8.1.7
+7 major composer:symfony/psr-http-message-bridge
defined in: drupal/drupal
1.0.2 8.1.0
+2 major composer:symfony/routing
defined in: bookstackapp/bookstack, drupal/drupal +1 more
6.4.12 8.1.6
+1 major composer:symfony/runtime
defined in: symfony/symfony-demo
7.1.1 8.1.0
+1 major composer:symfony/security-bundle
defined in: symfony/symfony-demo
7.1.1 8.1.7
+1 major composer:symfony/security-core
defined in: symfony/symfony-demo
7.1.1 8.1.6
+1 major composer:symfony/security-csrf
defined in: symfony/symfony-demo
7.1.1 8.1.0
+1 major composer:symfony/security-http
defined in: symfony/symfony-demo
7.1.1 8.1.7
+5 major composer:symfony/serializer
defined in: drupal/drupal
3.4.4 8.1.7
+1 major composer:symfony/stimulus-bundle
defined in: symfony/symfony-demo
2.17.0 3.5.1
+1 major composer:symfony/stopwatch
defined in: symfony/symfony-demo
7.1.1 8.1.0
+2 major composer:symfony/string
defined in: bookstackapp/bookstack, symfony/symfony-demo
6.4.12 8.1.7
+2 major composer:symfony/translation
defined in: bookstackapp/bookstack, drupal/drupal +1 more
6.4.12 8.1.5
+1 major composer:symfony/twig-bridge
defined in: symfony/symfony-demo
7.1.1 8.1.7
+1 major composer:symfony/twig-bundle
defined in: symfony/symfony-demo
7.1.1 8.1.7
+1 major composer:symfony/type-info
defined in: symfony/symfony-demo
7.1.1 8.1.5
+2 major composer:symfony/uid
defined in: bookstackapp/bookstack
6.4.12 8.1.5
+1 major composer:symfony/ux-live-component
defined in: symfony/symfony-demo
2.17.0 3.5.1
+1 major composer:symfony/ux-twig-component
defined in: symfony/symfony-demo
2.17.0 3.5.1
+5 major composer:symfony/validator
defined in: drupal/drupal, symfony/symfony-demo
3.4.4 8.1.7
+2 major composer:symfony/var-dumper
defined in: bookstackapp/bookstack, symfony/symfony-demo
6.4.11 8.1.7
+1 major composer:symfony/var-exporter
defined in: symfony/symfony-demo
7.1.1 8.1.6
+1 major composer:symfony/web-profiler-bundle
defined in: symfony/symfony-demo
7.1.1 8.1.7
+5 major composer:symfony/yaml
defined in: drupal/drupal, symfony/symfony-demo
3.4.5 8.1.6
+1 major composer:theseer/tokenizer
defined in: bookstackapp/bookstack
1.2.3 2.0.1
+1 major composer:twbs/bootstrap
defined in: symfony/symfony-demo
4.6.2 5.3.8
+2 major composer:twig/twig
defined in: drupal/drupal, symfony/symfony-demo
1.35.0 3.29.0
+1 major composer:webmozart/assert
defined in: bookstackapp/bookstack
1.11.0 2.4.1
+1 major composer:wikimedia/composer-merge-plugin
defined in: drupal/drupal
1.4.1 2.1.0
+74 minor composer:aws/aws-sdk-php
defined in: bookstackapp/bookstack
3.322.6 3.396.0
+1 minor composer:bacon/bacon-qr-code
defined in: bookstackapp/bookstack
3.0.0 3.1.1
+13 minor composer:behat/mink
defined in: drupal/drupal
dev-master 1.13.0
+7 minor composer:behat/mink-selenium2-driver
defined in: drupal/drupal
dev-master 1.7.0
+4 minor composer:dama/doctrine-test-bundle
defined in: symfony/symfony-demo
8.2.0 8.6.0
+1 minor composer:doctrine/event-manager
defined in: bookstackapp/bookstack, symfony/symfony-demo
2.0.1 2.1.1
+1 minor composer:doctrine/inflector
defined in: bookstackapp/bookstack, drupal/drupal +1 more
2.0.10 2.1.0
+1 minor composer:doctrine/instantiator
defined in: drupal/drupal, symfony/symfony-demo
2.0.0 2.1.0
+2 minor composer:doctrine/migrations
defined in: symfony/symfony-demo
3.7.4 3.9.7
+5 minor composer:doctrine/orm
defined in: symfony/symfony-demo
3.2.0 3.7.2
+1 minor composer:doctrine/sql-formatter
defined in: symfony/symfony-demo
1.4.0 1.5.4
+1 minor composer:dompdf/dompdf
defined in: bookstackapp/bookstack
3.0.0 3.1.6
+3 minor composer:dragonmantank/cron-expression
defined in: bookstackapp/bookstack
3.3.3 3.6.0
+1 minor composer:fakerphp/faker
defined in: bookstackapp/bookstack
1.23.1 1.24.1
+2 minor composer:filp/whoops
defined in: bookstackapp/bookstack
2.16.0 2.18.5
+1 minor composer:fruitcake/php-cors
defined in: bookstackapp/bookstack
1.3.0 1.4.0
+1 minor composer:graham-campbell/result-type
defined in: bookstackapp/bookstack
1.1.3 1.2.0
+1 minor composer:itsgoingd/clockwork
defined in: bookstackapp/bookstack
5.2.2 5.3.5
+2 minor composer:jcalderonzumba/gastonjs
defined in: drupal/drupal
1.0.2 1.2.0
+2 minor composer:knplabs/knp-snappy
defined in: bookstackapp/bookstack
1.5.0 1.7.3
+2 minor composer:laravel/prompts
defined in: bookstackapp/bookstack
0.1.25 0.3.24
+15 minor composer:laravel/socialite
defined in: bookstackapp/bookstack
5.16.0 5.31.0
+5 minor composer:league/commonmark
defined in: bookstackapp/bookstack, symfony/symfony-demo
2.5.3 2.10.3
+8 minor composer:league/flysystem
defined in: bookstackapp/bookstack
3.28.0 3.36.0
+7 minor composer:league/flysystem-aws-s3-v3
defined in: bookstackapp/bookstack
3.28.0 3.35.3
+7 minor composer:league/flysystem-local
defined in: bookstackapp/bookstack
3.28.0 3.35.3
+1 minor composer:league/mime-type-detection
defined in: bookstackapp/bookstack
1.16.0 1.17.0
+2 minor composer:league/oauth1-client
defined in: bookstackapp/bookstack
1.10.1 1.12.0
+2 minor composer:league/oauth2-client
defined in: bookstackapp/bookstack
2.7.0 2.9.1
+4 minor composer:league/uri
defined in: symfony/symfony-demo
7.4.1 7.8.1
+4 minor composer:league/uri-interfaces
defined in: symfony/symfony-demo
7.4.1 7.8.1
+2 minor composer:masterminds/html5
defined in: bookstackapp/bookstack, drupal/drupal +1 more
2.9.0 2.11.0
+5 minor composer:monolog/monolog
defined in: bookstackapp/bookstack, symfony/symfony-demo
3.7.0 3.12.0
+1 minor composer:mtdowling/jmespath.php
defined in: bookstackapp/bookstack
2.8.0 2.9.2
+2 minor composer:myclabs/deep-copy
defined in: bookstackapp/bookstack
1.12.0 1.14.0
+1 minor composer:nette/utils
defined in: bookstackapp/bookstack, symfony/symfony-demo
4.0.5 4.1.5
+7 minor composer:nikic/php-parser
defined in: bookstackapp/bookstack, symfony/symfony-demo
5.2.0 5.9.0
+1 minor composer:onelogin/php-saml
defined in: bookstackapp/bookstack
4.2.0 4.3.2
+1 minor composer:paragonie/constant_time_encoding
defined in: bookstackapp/bookstack
3.0.0 3.1.3
+1 minor composer:phpoption/phpoption
defined in: bookstackapp/bookstack
1.9.3 1.10.0
+19 minor composer:phpspec/prophecy
defined in: drupal/drupal
1.7.0 1.26.1
+1 minor composer:phpstan/extension-installer
defined in: symfony/symfony-demo
1.3.1 1.4.3
+1 minor composer:ramsey/collection
defined in: bookstackapp/bookstack
2.0.0 2.1.1
+2 minor composer:ramsey/uuid
defined in: bookstackapp/bookstack
4.7.6 4.9.4
+4 minor composer:socialiteproviders/manager
defined in: bookstackapp/bookstack
4.6.0 4.10.0
+1 minor composer:socialiteproviders/okta
defined in: bookstackapp/bookstack
4.4.0 4.5.0
+2 minor composer:ssddanbrown/asserthtml
defined in: bookstackapp/bookstack
3.0.0 3.2.0
+2 minor composer:symfony/cache-contracts
defined in: symfony/symfony-demo
3.5.0 3.7.1
+2 minor composer:symfony/deprecation-contracts
defined in: bookstackapp/bookstack, symfony/symfony-demo
3.5.0 3.7.1
+2 minor composer:symfony/event-dispatcher-contracts
defined in: bookstackapp/bookstack, symfony/symfony-demo
3.5.0 3.7.1
+7 minor composer:symfony/flex
defined in: symfony/symfony-demo
2.4.5 2.11.0
+2 minor composer:symfony/http-client-contracts
defined in: symfony/symfony-demo
3.5.0 3.7.3
+9 minor composer:symfony/maker-bundle
defined in: symfony/symfony-demo
1.59.1 1.68.0
+6 minor composer:symfony/polyfill-ctype
defined in: bookstackapp/bookstack, symfony/symfony-demo
1.31.0 1.37.0
+31 minor composer:symfony/polyfill-iconv
defined in: drupal/drupal
1.6.0 1.37.0
+10 minor composer:symfony/polyfill-intl-grapheme
defined in: bookstackapp/bookstack, symfony/symfony-demo
1.31.0 1.41.0
+9 minor composer:symfony/polyfill-intl-icu
defined in: symfony/symfony-demo
1.29.0 1.38.0
+11 minor composer:symfony/polyfill-intl-idn
defined in: bookstackapp/bookstack, symfony/symfony-demo
1.31.0 1.42.0
+9 minor composer:symfony/polyfill-intl-messageformatter
defined in: symfony/symfony-demo
1.29.0 1.38.0
+11 minor composer:symfony/polyfill-intl-normalizer
defined in: bookstackapp/bookstack, symfony/symfony-demo
1.31.0 1.42.0
+7 minor composer:symfony/polyfill-mbstring
defined in: bookstackapp/bookstack, drupal/drupal +1 more
1.31.0 1.38.2
+14 minor composer:symfony/polyfill-php70
defined in: drupal/drupal
1.6.0 1.20.0
+6 minor composer:symfony/polyfill-php80
defined in: bookstackapp/bookstack
1.31.0 1.37.0
+10 minor composer:symfony/polyfill-php83
defined in: bookstackapp/bookstack, symfony/symfony-demo
1.31.0 1.41.0
+6 minor composer:symfony/polyfill-uuid
defined in: bookstackapp/bookstack
1.31.0 1.37.0
+2 minor composer:symfony/service-contracts
defined in: bookstackapp/bookstack, symfony/symfony-demo
3.5.0 3.7.3
+2 minor composer:symfony/translation-contracts
defined in: bookstackapp/bookstack, symfony/symfony-demo
3.5.0 3.7.1
+7 minor composer:symfonycasts/sass-bundle
defined in: symfony/symfony-demo
0.3.0 0.10.0
+2 minor composer:tijsverkoyen/css-to-inline-styles
defined in: bookstackapp/bookstack
2.2.7 2.4.0
+19 minor composer:twig/extra-bundle
defined in: symfony/symfony-demo
3.10.0 3.29.0
+19 minor composer:twig/intl-extra
defined in: symfony/symfony-demo
3.10.0 3.29.0
+19 minor composer:twig/markdown-extra
defined in: symfony/symfony-demo
3.10.0 3.29.0
+1 minor composer:vlucas/phpdotenv
defined in: bookstackapp/bookstack
5.6.1 5.7.0
+1 minor composer:voku/portable-ascii
defined in: bookstackapp/bookstack
2.0.1 2.1.1
+1 patch composer:aws/aws-crt-php
defined in: bookstackapp/bookstack
1.2.6 1.2.7
+1 patch composer:dasprid/enum
defined in: bookstackapp/bookstack
1.0.6 1.0.7
+3 patch composer:doctrine/deprecations
defined in: bookstackapp/bookstack, symfony/symfony-demo
1.1.3 1.1.6
+1 patch composer:doctrine/lexer
defined in: bookstackapp/bookstack, drupal/drupal +1 more
3.0.1 3.0.2
+2 patch composer:dompdf/php-font-lib
defined in: bookstackapp/bookstack
1.0.0 1.0.2
+2 patch composer:dompdf/php-svg-lib
defined in: bookstackapp/bookstack
1.0.0 1.0.2
+2 patch composer:egulias/email-validator
defined in: bookstackapp/bookstack, drupal/drupal +1 more
4.0.2 4.0.4
+15 patch composer:instaclick/php-webdriver
defined in: drupal/drupal
1.4.5 1.4.20
+1 patch composer:jcalderonzumba/mink-phantomjs-driver
defined in: drupal/drupal
0.3.2 0.3.3
+1 patch composer:league/html-to-markdown
defined in: bookstackapp/bookstack
5.1.1 5.1.2
+7 patch composer:mikey179/vfsStream
defined in: drupal/drupal
1.6.5 1.6.12
+3 patch composer:mockery/mockery
defined in: bookstackapp/bookstack
1.6.12 1.6.15
+6 patch composer:nette/schema
defined in: bookstackapp/bookstack, symfony/symfony-demo
1.3.0 1.3.6
+20 patch composer:psy/psysh
defined in: bookstackapp/bookstack
0.12.4 0.12.24
+1 patch composer:socialiteproviders/microsoft-azure
defined in: bookstackapp/bookstack
5.2.0 5.2.1

4. Licenses (251, 4 to review)

4 dependency(ies) carry a copyleft, proprietary, or unrecognized license that may impose redistribution obligations — review against your distribution model. Permissive licenses are listed for completeness.

Strong copyleft (GPL) 4

DependencyLicense(s)Source
composer:
drupal/coder
8.2.12 direct dev
defined in: drupal/drupal
GPL-2.0 packagist
composer:
nette/schema
1.3.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
BSD-3-Clause, GPL-2.0-only, GPL-3.0-only packagist
composer:
nette/utils
4.0.5 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
BSD-3-Clause, GPL-2.0-only, GPL-3.0-only packagist
composer:
phpmyadmin/sql-parser
5.10.0 direct dev
defined in: bookstackapp/bookstack
GPL-2.0-or-later packagist

Weak copyleft (LGPL/MPL/EPL) 3

DependencyLicense(s)Source
composer:
dompdf/dompdf
3.0.0 direct
defined in: bookstackapp/bookstack
LGPL-2.1 packagist
composer:
dompdf/php-font-lib
1.0.0 direct
defined in: bookstackapp/bookstack
LGPL-2.1-or-later packagist
composer:
dompdf/php-svg-lib
1.0.0 direct
defined in: bookstackapp/bookstack
LGPL-3.0-or-later packagist

Permissive (MIT/Apache/BSD) 244

DependencyLicense(s)Source
composer:
asm89/stack-cors
1.2.0 direct
defined in: drupal/drupal
MIT packagist
composer:
aws/aws-crt-php
1.2.6 direct
defined in: bookstackapp/bookstack
Apache-2.0 packagist
composer:
aws/aws-sdk-php
3.322.6 direct
defined in: bookstackapp/bookstack
Apache-2.0 packagist
composer:
bacon/bacon-qr-code
3.0.0 direct
defined in: bookstackapp/bookstack
BSD-2-Clause packagist
composer:
behat/mink
dev-master direct dev
defined in: drupal/drupal
MIT packagist
composer:
behat/mink-browserkit-driver
1.3.2 direct dev
defined in: drupal/drupal
MIT packagist
composer:
behat/mink-goutte-driver
1.2.1 direct dev
defined in: drupal/drupal
MIT packagist
composer:
behat/mink-selenium2-driver
dev-master direct dev
defined in: drupal/drupal
MIT packagist
composer:
brick/math
0.12.1 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
carbonphp/carbon-doctrine-types
2.1.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
composer/installers
1.5.0 direct
defined in: drupal/drupal
MIT packagist
composer:
composer/semver
1.4.2 direct
defined in: drupal/drupal, symfony/symfony-demo
MIT packagist
composer:
dama/doctrine-test-bundle
8.2.0 direct dev
defined in: symfony/symfony-demo
MIT packagist
composer:
dasprid/enum
1.0.6 direct
defined in: bookstackapp/bookstack
BSD-2-Clause packagist
composer:
dflydev/dot-access-data
3.0.3 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
doctrine/annotations
1.2.7 direct
defined in: drupal/drupal
MIT packagist
composer:
doctrine/cache
2.2.0 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
doctrine/collections
1.3.0 direct
defined in: drupal/drupal, symfony/symfony-demo
MIT packagist
composer:
doctrine/common
2.6.2 direct
defined in: drupal/drupal
MIT packagist
composer:
doctrine/data-fixtures
1.7.0 direct dev
defined in: symfony/symfony-demo
MIT packagist
composer:
doctrine/dbal
3.9.1 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
doctrine/deprecations
1.1.3 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
doctrine/doctrine-bundle
2.12.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
doctrine/doctrine-fixtures-bundle
3.6.1 direct dev
defined in: symfony/symfony-demo
MIT packagist
composer:
doctrine/doctrine-migrations-bundle
3.3.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
doctrine/event-manager
2.0.1 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
doctrine/inflector
2.0.10 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
doctrine/instantiator
2.0.0 direct
defined in: drupal/drupal, symfony/symfony-demo
MIT packagist
composer:
doctrine/lexer
3.0.1 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
doctrine/migrations
3.7.4 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
doctrine/orm
3.2.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
doctrine/persistence
3.3.2 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
doctrine/sql-formatter
1.4.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
dragonmantank/cron-expression
3.3.3 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
easyrdf/easyrdf
0.9.1 direct
defined in: drupal/drupal
BSD-3-Clause packagist
composer:
egulias/email-validator
4.0.2 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
fabpot/goutte
3.2.1 direct dev
defined in: drupal/drupal
MIT packagist
composer:
fakerphp/faker
1.23.1 direct dev
defined in: bookstackapp/bookstack
MIT packagist
composer:
filp/whoops
2.16.0 direct dev
defined in: bookstackapp/bookstack
MIT packagist
composer:
firebase/php-jwt
6.10.1 direct
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
fruitcake/php-cors
1.3.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
graham-campbell/result-type
1.1.3 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
guzzlehttp/guzzle
7.9.2 direct
defined in: bookstackapp/bookstack, drupal/drupal
MIT packagist
composer:
guzzlehttp/promises
2.0.3 direct
defined in: bookstackapp/bookstack, drupal/drupal
MIT packagist
composer:
guzzlehttp/psr7
2.7.0 direct
defined in: bookstackapp/bookstack, drupal/drupal
MIT packagist
composer:
guzzlehttp/uri-template
1.0.3 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
hamcrest/hamcrest-php
2.0.1 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
instaclick/php-webdriver
1.4.5 direct dev
defined in: drupal/drupal
Apache-2.0 packagist
composer:
intervention/gif
4.2.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
intervention/image
3.8.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
ircmaxell/password-compat
1.0.4 direct dev
defined in: drupal/drupal
MIT packagist
composer:
itsgoingd/clockwork
5.2.2 direct dev
defined in: bookstackapp/bookstack
MIT packagist
composer:
jcalderonzumba/gastonjs
1.0.2 direct dev
defined in: drupal/drupal
MIT packagist
composer:
jcalderonzumba/mink-phantomjs-driver
0.3.2 direct dev
defined in: drupal/drupal
MIT packagist
composer:
knplabs/knp-snappy
1.5.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
larastan/larastan
2.9.8 direct dev
defined in: bookstackapp/bookstack
MIT packagist
composer:
laravel/framework
10.48.22 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
laravel/prompts
0.1.25 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
laravel/serializable-closure
1.3.5 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
laravel/socialite
5.16.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
laravel/tinker
2.10.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
league/commonmark
2.5.3 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
BSD-3-Clause packagist
composer:
league/config
1.2.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
BSD-3-Clause packagist
composer:
league/flysystem
3.28.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
league/flysystem-aws-s3-v3
3.28.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
league/flysystem-local
3.28.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
league/html-to-markdown
5.1.1 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
league/mime-type-detection
1.16.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
league/oauth1-client
1.10.1 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
league/oauth2-client
2.7.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
league/uri
7.4.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
league/uri-interfaces
7.4.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
masterminds/html5
2.9.0 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
mikey179/vfsStream
1.6.5 direct dev
defined in: drupal/drupal
BSD-3-Clause packagist
composer:
mockery/mockery
1.6.12 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
monolog/monolog
3.7.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
mtdowling/jmespath.php
2.8.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
myclabs/deep-copy
1.12.0 direct dev
defined in: bookstackapp/bookstack
MIT packagist
composer:
nesbot/carbon
2.72.5 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
nikic/php-parser
5.2.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
BSD-3-Clause packagist
composer:
nunomaduro/collision
7.10.0 direct dev
defined in: bookstackapp/bookstack
MIT packagist
composer:
nunomaduro/termwind
1.15.1 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
onelogin/php-saml
4.2.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
paragonie/constant_time_encoding
3.0.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
paragonie/random_compat
9.99.100 direct
defined in: bookstackapp/bookstack, drupal/drupal
MIT packagist
composer:
phar-io/manifest
2.0.4 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
phar-io/version
3.2.1 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
phpdocumentor/reflection-docblock
2.0.4 direct dev
defined in: drupal/drupal
MIT packagist
composer:
phpoption/phpoption
1.9.3 direct
defined in: bookstackapp/bookstack
Apache-2.0 packagist
composer:
phpseclib/phpseclib
3.0.42 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
phpspec/prophecy
1.7.0 direct dev
defined in: drupal/drupal
MIT packagist
composer:
phpstan/extension-installer
1.3.1 direct dev
defined in: symfony/symfony-demo
MIT packagist
composer:
phpstan/phpstan
1.12.5 direct dev
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
phpstan/phpstan-doctrine
1.4.1 direct dev
defined in: symfony/symfony-demo
MIT packagist
composer:
phpstan/phpstan-symfony
1.4.3 direct dev
defined in: symfony/symfony-demo
MIT packagist
composer:
phpunit/php-code-coverage
10.1.16 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
phpunit/php-file-iterator
4.1.0 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
phpunit/php-invoker
4.0.0 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
phpunit/php-text-template
3.0.1 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
phpunit/php-timer
6.0.0 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
phpunit/php-token-stream
1.4.11 direct dev
defined in: drupal/drupal
BSD-3-Clause packagist
composer:
phpunit/phpunit
10.5.35 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
phpunit/phpunit-mock-objects
2.3.8 direct dev
defined in: drupal/drupal
BSD-3-Clause packagist
composer:
pragmarx/google2fa
8.0.3 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
predis/predis
2.2.2 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
psr/cache
3.0.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
psr/clock
1.0.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
psr/container
2.0.2 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
psr/event-dispatcher
1.0.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
psr/http-client
1.0.3 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
psr/http-factory
1.1.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
psr/http-message
2.0 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
psr/log
3.0.2 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
psr/simple-cache
3.0.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
psy/psysh
0.12.4 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
ralouphie/getallheaders
3.0.3 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
ramsey/collection
2.0.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
ramsey/uuid
4.7.6 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
robrichards/xmlseclibs
3.1.1 direct
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
sabberworm/php-css-parser
8.6.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
sebastian/cli-parser
2.0.1 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
sebastian/code-unit
2.0.0 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
sebastian/code-unit-reverse-lookup
3.0.0 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
sebastian/comparator
5.0.2 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
sebastian/complexity
3.2.0 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
sebastian/diff
5.1.1 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
sebastian/environment
6.1.0 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
sebastian/exporter
5.1.2 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
sebastian/global-state
6.0.2 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
sebastian/lines-of-code
2.0.2 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
sebastian/object-enumerator
5.0.0 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
sebastian/object-reflector
3.0.0 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
sebastian/recursion-context
5.0.0 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
sebastian/type
4.0.0 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
sebastian/version
4.0.1 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
socialiteproviders/discord
4.2.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
socialiteproviders/gitlab
4.1.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
socialiteproviders/manager
4.6.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
socialiteproviders/microsoft-azure
5.2.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
socialiteproviders/okta
4.4.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
socialiteproviders/twitch
5.4.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
squizlabs/php_codesniffer
3.10.3 direct dev
defined in: bookstackapp/bookstack, drupal/drupal
BSD-3-Clause packagist
composer:
ssddanbrown/asserthtml
3.0.0 direct dev
defined in: bookstackapp/bookstack
MIT packagist
composer:
ssddanbrown/htmldiff
1.0.3 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
ssddanbrown/symfony-mailer
6.4.x-dev direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
stack/builder
1.0.5 direct
defined in: drupal/drupal
MIT packagist
composer:
symfony-cmf/routing
1.4.1 direct
defined in: drupal/drupal
MIT packagist
composer:
symfony/apache-pack
1.0.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/asset
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/asset-mapper
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/browser-kit
3.4.4 direct dev
defined in: drupal/drupal, symfony/symfony-demo
MIT packagist
composer:
symfony/cache
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/cache-contracts
3.5.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/class-loader
3.4.4 direct
defined in: drupal/drupal
MIT packagist
composer:
symfony/clock
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/config
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/console
6.4.12 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
symfony/css-selector
6.4.8 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
symfony/debug
3.4.4 direct
defined in: drupal/drupal
MIT packagist
composer:
symfony/debug-bundle
7.1.1 direct dev
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/dependency-injection
3.4.4 direct
defined in: drupal/drupal, symfony/symfony-demo
MIT packagist
composer:
symfony/deprecation-contracts
3.5.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/doctrine-bridge
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/dom-crawler
6.4.12 direct dev
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
symfony/dotenv
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/error-handler
6.4.10 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/event-dispatcher
6.4.8 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
symfony/event-dispatcher-contracts
3.5.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/expression-language
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/filesystem
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/finder
6.4.11 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/flex
2.4.5 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/form
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/framework-bundle
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/html-sanitizer
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/http-client
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/http-client-contracts
3.5.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/http-foundation
6.4.12 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
symfony/http-kernel
6.4.12 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
symfony/intl
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/mailer
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/maker-bundle
1.59.1 direct dev
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/mime
6.4.12 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/monolog-bridge
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/monolog-bundle
3.10.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/options-resolver
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/password-hasher
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/phpunit-bridge
3.4.4 direct dev
defined in: drupal/drupal, symfony/symfony-demo
MIT packagist
composer:
symfony/polyfill-ctype
1.31.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/polyfill-iconv
1.6.0 direct
defined in: drupal/drupal
MIT packagist
composer:
symfony/polyfill-intl-grapheme
1.31.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/polyfill-intl-icu
1.29.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/polyfill-intl-idn
1.31.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/polyfill-intl-messageformatter
1.29.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/polyfill-intl-normalizer
1.31.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/polyfill-mbstring
1.31.0 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
symfony/polyfill-php70
1.6.0 direct
defined in: drupal/drupal
MIT packagist
composer:
symfony/polyfill-php80
1.31.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
symfony/polyfill-php83
1.31.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/polyfill-uuid
1.31.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
symfony/process
6.4.12 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
symfony/property-access
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/property-info
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/psr-http-message-bridge
1.0.2 direct
defined in: drupal/drupal
MIT packagist
composer:
symfony/routing
6.4.12 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
symfony/runtime
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/security-bundle
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/security-core
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/security-csrf
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/security-http
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/serializer
3.4.4 direct
defined in: drupal/drupal
MIT packagist
composer:
symfony/service-contracts
3.5.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/stimulus-bundle
2.17.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/stopwatch
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/string
6.4.12 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/translation
6.4.12 direct
defined in: bookstackapp/bookstack, drupal/drupal +1 more
MIT packagist
composer:
symfony/translation-contracts
3.5.0 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/twig-bridge
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/twig-bundle
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/type-info
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/uid
6.4.12 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
symfony/ux-live-component
2.17.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/ux-twig-component
2.17.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/validator
3.4.4 direct
defined in: drupal/drupal, symfony/symfony-demo
MIT packagist
composer:
symfony/var-dumper
6.4.11 direct
defined in: bookstackapp/bookstack, symfony/symfony-demo
MIT packagist
composer:
symfony/var-exporter
7.1.1 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/web-profiler-bundle
7.1.1 direct dev
defined in: symfony/symfony-demo
MIT packagist
composer:
symfony/yaml
3.4.5 direct
defined in: drupal/drupal, symfony/symfony-demo
MIT packagist
composer:
symfonycasts/sass-bundle
0.3.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
theseer/tokenizer
1.2.3 direct dev
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
tijsverkoyen/css-to-inline-styles
2.2.7 direct
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
twbs/bootstrap
4.6.2 direct dev
defined in: symfony/symfony-demo
MIT packagist
composer:
twig/extra-bundle
3.10.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
twig/intl-extra
3.10.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
twig/markdown-extra
3.10.0 direct
defined in: symfony/symfony-demo
MIT packagist
composer:
twig/twig
1.35.0 direct
defined in: drupal/drupal, symfony/symfony-demo
BSD-3-Clause packagist
composer:
vlucas/phpdotenv
5.6.1 direct
defined in: bookstackapp/bookstack
BSD-3-Clause packagist
composer:
voku/portable-ascii
2.0.1 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
webmozart/assert
1.11.0 direct
defined in: bookstackapp/bookstack
MIT packagist
composer:
wikimedia/composer-merge-plugin
1.4.1 direct
defined in: drupal/drupal
MIT packagist
composer:
zendframework/zend-diactoros
1.4.1 direct
defined in: drupal/drupal
BSD-2-Clause packagist
composer:
zendframework/zend-escaper
2.5.2 direct
defined in: drupal/drupal
BSD-3-Clause packagist
composer:
zendframework/zend-feed
2.7.0 direct
defined in: drupal/drupal
BSD-3-Clause packagist
composer:
zendframework/zend-stdlib
3.0.1 direct
defined in: drupal/drupal
BSD-3-Clause packagist

5. Fix Recommendations

5.1 Direct deps to update (39)

Every direct dep with at least one CVE matched. The "Pin to ≥" column shows the highest fix-version declared across the CVEs for that dep. When that's missing, the dep needs a manual triage (no clean fix is published).
Worst sevDirect dependencyCurrentPin to ≥Maven Central latestCVEs covered
CRITICAL composer:twig/twig 1.35.0 3.27.0 — 35 CVE: CVE-2026-46633, CVE-2026-46633, CVE-2022-39261, CVE-2026-24425…
CRITICAL composer:drupal/core 8.5.0 10.6.13 — 16 CVE: CVE-2018-7600, CVE-2018-7602, CVE-2026-55803, CVE-2018-9861…
CRITICAL composer:symfony/http-foundation 3.4.4 7.2.0 — 12 CVE: CVE-2019-10913, CVE-2019-18888, CVE-2025-64500, CVE-2025-64500…
CRITICAL composer:symfony/dependency-injection 3.4.4 3.4.26 — 1 CVE: CVE-2019-10910
CRITICAL composer:mtdowling/jmespath.php 2.8.0 2.9.1 — 1 CVE: CVE-2026-54133
CRITICAL composer:onelogin/php-saml 4.2.0 4.3.1 — 1 CVE: GHSA-5j8p-438x-rgg5
HIGH composer:league/commonmark 2.5.3 2.10.0 — 26 CVE: CVE-2024-58382, CVE-2024-58382, CVE-2026-71488, CVE-2026-71488…
HIGH composer:guzzlehttp/guzzle 6.3.0 7.15.2 — 22 CVE: CVE-2022-29248, CVE-2022-31042, CVE-2022-31090, CVE-2022-31091…
HIGH composer:symfony/process 6.4.12 7.1.7 — 5 CVE: CVE-2024-51736, CVE-2024-51736, CVE-2024-51736, CVE-2026-24739…
HIGH composer:symfony/security-http 7.1.1 7.2.0 — 4 CVE: CVE-2024-51996, CVE-2026-45063, CVE-2026-48489, CVE-2026-45074
HIGH composer:laravel/framework 10.48.22 12.61.1 — 4 CVE: CVE-2024-52301, CVE-2026-48019, CVE-2025-27515, GHSA-crmm-hgp2-wgrp
HIGH composer:phpseclib/phpseclib 3.0.42 3.0.51 — 4 CVE: CVE-2026-32935, CVE-2026-44167, CVE-2026-55599, CVE-2026-40194
HIGH composer:symfony/mime 6.4.12 7.2.0 — 4 CVE: CVE-2026-45067, CVE-2026-45067, CVE-2026-45070, CVE-2026-45070
HIGH composer:symfony/http-kernel 3.4.4 4.0.0 — 2 CVE: CVE-2019-18887, CVE-2022-24894
HIGH composer:robrichards/xmlseclibs 3.1.1 3.1.5 — 2 CVE: CVE-2026-32313, CVE-2025-66578
HIGH composer:knplabs/knp-snappy 1.5.0 — (manual triage) — 2 CVE: CVE-2026-46643, CVE-2026-46683
HIGH composer:aws/aws-sdk-php 3.322.6 3.368.0 — 2 CVE: GHSA-27qh-8cxx-2cr5, CVE-2025-14761
HIGH composer:zendframework/zend-diactoros 1.4.1 1.8.4 — 2 CVE: GHSA-f6p5-76fp-m248, GHSA-fq4p-86hh-42v9
HIGH composer:zendframework/zend-feed 2.7.0 2.10.3 — 2 CVE: GHSA-f6p5-76fp-m248, GHSA-jmmp-vh96-78rm
HIGH composer:symfony/monolog-bridge 7.1.1 7.2.0 — 1 CVE: CVE-2026-45077
MEDIUM composer:guzzlehttp/psr7 1.4.2 2.12.3 — 10 CVE: CVE-2022-24775, CVE-2023-29197, CVE-2026-48998, CVE-2026-48998…
MEDIUM composer:symfony/routing 6.4.12 7.2.0 — 6 CVE: CVE-2026-45065, CVE-2026-45065, CVE-2026-45065, CVE-2026-48784…
MEDIUM composer:dompdf/dompdf 3.0.0 3.1.6 — 6 CVE: CVE-2026-56722, CVE-2026-59941, CVE-2026-59942, CVE-2026-59943…
MEDIUM composer:symfony/ux-live-component 2.17.0 2.36.0 — 5 CVE: CVE-2025-47946, CVE-2026-49208, CVE-2026-49210, CVE-2026-49209…
MEDIUM composer:symfony/html-sanitizer 7.1.1 7.2.0 — 5 CVE: CVE-2026-45064, CVE-2026-45066, CVE-2026-48760, CVE-2026-48761…
MEDIUM composer:symfony/runtime 7.1.1 7.1.7 — 1 CVE: CVE-2024-50340
MEDIUM composer:nesbot/carbon 2.72.5 2.72.6 — 1 CVE: CVE-2025-22145
MEDIUM composer:symfony/ux-twig-component 2.17.0 2.25.1 — 1 CVE: CVE-2025-47946
MEDIUM composer:psy/psysh 0.12.4 — (manual triage) — 1 CVE: CVE-2026-25129
MEDIUM composer:symfony/mailer 7.1.1 7.2.0 — 1 CVE: CVE-2026-45068
MEDIUM composer:symfony/cache 7.1.1 7.2.0 — 1 CVE: CVE-2026-45073
LOW composer:symfony/yaml 3.4.5 7.2.0 — 6 CVE: CVE-2026-45133, CVE-2026-45133, CVE-2026-45304, CVE-2026-45304…
LOW composer:symfony/validator 3.4.4 7.1.4 — 2 CVE: CVE-2024-50343, CVE-2024-50343
LOW composer:symfony/polyfill-intl-idn 1.31.0 1.38.1 — 2 CVE: CVE-2026-46644, CVE-2026-46644
LOW composer:symfony/security-bundle 7.1.1 7.1.3 — 1 CVE: CVE-2024-50341
LOW composer:symfony/http-client 7.1.1 7.1.8 — 1 CVE: CVE-2024-50342
LOW composer:firebase/php-jwt 6.10.1 7.0.0 — 1 CVE: CVE-2025-45769
LOW composer:twig/intl-extra 3.10.0 3.26.0 — 1 CVE: CVE-2026-46629
LOW composer:twig/markdown-extra 3.10.0 3.26.0 — 1 CVE: CVE-2026-46637

6. Scan context & limitations

6.1 Scanned dependency descriptors (30)

Every manifest / lockfile descriptor fad-checker parsed for this scan (paths relative to the source root) — the complete list, including files that contributed no scannable dependency (only version ranges, or no lockfile): 27 such files shown with 0. Transitive deps resolved from registries, and committed binaries (chapters 1B/1C), are not descriptors and are excluded here.
DescriptorEcosystemDirect deps
bookstack/composer.json Composer 0 — ranges / no lockfile
bookstack/composer.lock Composer 147
drupal/composer.json Composer 0 — ranges / no lockfile
drupal/composer.lock Composer 77
drupal/core/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Annotation/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Assertion/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Bridge/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/ClassFinder/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Datetime/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/DependencyInjection/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Diff/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Discovery/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/EventDispatcher/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/FileCache/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/FileSystem/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Gettext/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Graph/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/HttpFoundation/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/PhpStorage/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Plugin/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/ProxyBuilder/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Render/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Serialization/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Transliteration/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Utility/composer.json Composer 0 — ranges / no lockfile
drupal/core/lib/Drupal/Component/Uuid/composer.json Composer 0 — ranges / no lockfile
symfony-demo/composer.json Composer 0 — ranges / no lockfile
symfony-demo/composer.lock Composer 118
wp/wp-includes/sodium_compat/composer.json Composer 0 — ranges / no lockfile

6.2 Ignored directories (130)

Directories the scan did not walk — pruned by the built-in default-exclude set (package stores, build output, VCS/IDE metadata) at any depth and by your --exclude-path rules, anchored to --src. Paths are relative to the scan root. 8 pruned by default rules, 122 by --exclude-path. Nothing under these paths was read, so any dependency, vendored JS or binary inside them is not covered — re-run with --no-default-excludes or drop an --exclude-path rule to include one.
Directory (relative to --src)RuleMatched
bookstack/dev/builddefaultdefault-exclude (build)
bookstack/public/distdefaultdefault-exclude (dist)
bookstack/resources/views/vendordefaultdefault-exclude (vendor)
bookstack/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/assets/vendordefaultdefault-exclude (vendor)
drupal/core/lib/Drupal/Core/Test--exclude-path--exclude-path (**/Test/**)
drupal/core/modules/action/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/aggregator/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/aggregator/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/ban/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/basic_auth/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/basic_auth/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/big_pipe/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/block_content/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/block_content/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/block_place/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/block/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/block/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/book/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/breakpoint/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/ckeditor/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/color/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/comment/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/comment/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/config_translation/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/config_translation/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/config/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/config/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/contact/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/content_moderation/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/content_translation/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/content_translation/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/contextual/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/contextual/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/datetime_range/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/datetime/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/datetime/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/dblog/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/dynamic_page_cache/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/editor/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/editor/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/field_layout/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/field_ui/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/field_ui/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/field/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/field/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/file/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/file/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/filter/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/forum/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/hal/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/help/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/history/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/image/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/image/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/inline_form_errors/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/language/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/layout_builder/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/layout_discovery/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/link/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/link/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/locale/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/media/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/menu_link_content/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/menu_ui/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/menu_ui/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/migrate_drupal_ui/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/migrate_drupal_ui/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/migrate_drupal/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/migrate_drupal/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/migrate/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/node/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/node/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/options/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/page_cache/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/path/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/path/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/quickedit/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/quickedit/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/rdf/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/rdf/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/responsive_image/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/responsive_image/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/rest/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/rest/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/search/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/search/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/serialization/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/serialization/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/settings_tray/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/shortcut/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/shortcut/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/simpletest/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/simpletest/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/statistics/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/statistics/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/syslog/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/system/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/system/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/taxonomy/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/taxonomy/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/telephone/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/text/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/text/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/toolbar/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/tour/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/tour/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/tracker/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/tracker/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/update/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/update/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/user/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/user/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/views_ui/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/views_ui/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/views/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/modules/views/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/modules/workflows/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/profiles/demo_umami/modules/demo_umami_content/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/profiles/demo_umami/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/profiles/minimal/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/profiles/standard/tests--exclude-path--exclude-path (**/tests/**)
drupal/core/profiles/testing/modules/drupal_system_listing_compatible_test/src/Tests--exclude-path--exclude-path (**/Tests/**)
drupal/core/scripts/test--exclude-path--exclude-path (**/test/**)
drupal/core/tests--exclude-path--exclude-path (**/tests/**)
symfony-demo/bindefaultdefault-exclude (bin)
symfony-demo/config/packagesdefaultdefault-exclude (packages)
symfony-demo/tests--exclude-path--exclude-path (**/tests/**)
wp/wp-includes/css/distdefaultdefault-exclude (dist)
wp/wp-includes/js/distdefaultdefault-exclude (dist)

6.3 Methodology, data sources & limitations

How this report was produced and what it does not cover — stated for audit transparency and reproducibility. The data-source table shows the freshness of every feed used; the configuration line records the run's findings-affecting options. An --offline re-run against the same cache (ship it with --export-cache) reproduces these findings.
Data sourceStateAs ofDetail
CVEProject (Maven index)cached2026-09-24T06:54:21.297Z20191 CVEs
OSV.devcached2026-09-24T15:48:24.793Z20365 cached
Packagist security advisoriescached2026-09-24T15:47:29.429Z354 cached
OSV local DB (Maven)cached2026-09-24T06:56:13.134Z
NIST NVDcached2026-09-24T15:50:25.789Z2035 cached
EPSS (FIRST.org)cached2026-09-24T07:41:44.826Z743 entries
CISA KEVcached2026-09-24T15:47:29.624Z
endoflife.datecached2026-09-24T07:10:41.138Z18 entries
Maven Central (latest)cached2026-09-24T16:41:13.725Z284 entries
npm registrycached2026-09-24T15:57:57.979Z2694 entries
NuGet registrycached2026-09-19T14:06:03.234Z8 entries
Packagistcached2026-09-24T16:41:13.728Z625 entries
Go module proxycached2026-09-19T09:45:19.860Z12 entries
RubyGemscached2026-09-19T09:46:53.531Z6 entries
mode: offline ecosystems: composer transitive: on (depth 6) OSV: true NVD: true EPSS: true KEV: true licenses: true typosquat: false fail-on: none runtime: v24.14.0 · linux/x64
Limitations — fad-checker does not assess:
  • Reachability / exploitability in your app. Findings flag a vulnerable version on the dependency graph; they do not prove the vulnerable code path is actually called at runtime. Triage with your application context.
  • Runtime configuration & mitigations. WAFs, feature flags, network isolation, disabled features, and other compensating controls are not modelled.
  • Secrets, IaC & container base images. No secret scanning, infrastructure-as-code, or OS/base-image layer analysis — fad-checker scans declared & vendored application dependencies only.
  • Business-logic & first-party code flaws. No SAST of your own source; only third-party components are assessed.
  • Malware beyond the available signal. Supply-chain risk uses OSV MAL- advisories and the free CIRCL KnownMalicious flag; there is no antivirus/behavioural lane.
  • License legal advice. License classification is informational SPDX categorisation, not a legal determination.
  • Private / internal coordinates. Components absent from public registries can't be CVE-matched here; audit them against your internal feed.
  • Data-source recency. Results reflect the cache state in the data-source table above; an --offline run uses exactly those snapshots.

6.4 Application inventory & coverage

wordpress · wp

Warnings (102)

Missing files (100)
  • wp-content/plugins/akismet/_inc/akismet-admin.css
  • wp-content/plugins/akismet/_inc/akismet-admin.js
  • wp-content/plugins/akismet/_inc/akismet-frontend.js
  • wp-content/plugins/akismet/_inc/akismet.css
  • wp-content/plugins/akismet/_inc/akismet.js
  • wp-content/plugins/akismet/_inc/fonts/inter.css
  • wp-content/plugins/akismet/_inc/img/akismet-refresh-logo.svg
  • wp-content/plugins/akismet/_inc/img/akismet-refresh-logo@2x.png
  • wp-content/plugins/akismet/_inc/img/arrow-left.svg
  • wp-content/plugins/akismet/_inc/img/logo-a-2x.png
  • wp-content/plugins/akismet/_inc/img/logo-full-2x.png
  • wp-content/plugins/akismet/_inc/rtl/akismet-admin-rtl.css
  • wp-content/plugins/akismet/_inc/rtl/akismet-rtl.css
  • wp-content/plugins/akismet/.htaccess
  • wp-content/plugins/akismet/akismet.php
  • wp-content/plugins/akismet/changelog.txt
  • wp-content/plugins/akismet/class.akismet-admin.php
  • wp-content/plugins/akismet/class.akismet-cli.php
  • wp-content/plugins/akismet/class.akismet-rest-api.php
  • wp-content/plugins/akismet/class.akismet-widget.php
  • wp-content/plugins/akismet/class.akismet.php
  • wp-content/plugins/akismet/index.php
  • wp-content/plugins/akismet/LICENSE.txt
  • wp-content/plugins/akismet/readme.txt
  • wp-content/plugins/akismet/views/activate.php
  • wp-content/plugins/akismet/views/config.php
  • wp-content/plugins/akismet/views/connect-jp.php
  • wp-content/plugins/akismet/views/enter.php
  • wp-content/plugins/akismet/views/get.php
  • wp-content/plugins/akismet/views/logo.php
  • wp-content/plugins/akismet/views/notice.php
  • wp-content/plugins/akismet/views/predefined.php
  • wp-content/plugins/akismet/views/setup.php
  • wp-content/plugins/akismet/views/start.php
  • wp-content/plugins/akismet/views/stats.php
  • wp-content/plugins/akismet/views/title.php
  • wp-content/plugins/akismet/wrapper.php
  • wp-includes/css/dist/block-directory/style-rtl.css
  • wp-includes/css/dist/block-directory/style-rtl.min.css
  • wp-includes/css/dist/block-directory/style.css
  • wp-includes/css/dist/block-directory/style.min.css
  • wp-includes/css/dist/block-library/classic-rtl.css
  • wp-includes/css/dist/block-library/classic-rtl.min.css
  • wp-includes/css/dist/block-library/classic.css
  • wp-includes/css/dist/block-library/classic.min.css
  • wp-includes/css/dist/block-library/common-rtl.css
  • wp-includes/css/dist/block-library/common-rtl.min.css
  • wp-includes/css/dist/block-library/common.css
  • wp-includes/css/dist/block-library/common.min.css
  • wp-includes/css/dist/block-library/editor-elements-rtl.css
  • wp-includes/css/dist/block-library/editor-elements-rtl.min.css
  • wp-includes/css/dist/block-library/editor-elements.css
  • wp-includes/css/dist/block-library/editor-elements.min.css
  • wp-includes/css/dist/block-library/editor-rtl.css
  • wp-includes/css/dist/block-library/editor-rtl.min.css
  • wp-includes/css/dist/block-library/editor.css
  • wp-includes/css/dist/block-library/editor.min.css
  • wp-includes/css/dist/block-library/elements-rtl.css
  • wp-includes/css/dist/block-library/elements-rtl.min.css
  • wp-includes/css/dist/block-library/elements.css
  • wp-includes/css/dist/block-library/elements.min.css
  • wp-includes/css/dist/block-library/reset-rtl.css
  • wp-includes/css/dist/block-library/reset-rtl.min.css
  • wp-includes/css/dist/block-library/reset.css
  • wp-includes/css/dist/block-library/reset.min.css
  • wp-includes/css/dist/block-library/style-rtl.css
  • wp-includes/css/dist/block-library/style-rtl.min.css
  • wp-includes/css/dist/block-library/style.css
  • wp-includes/css/dist/block-library/style.min.css
  • wp-includes/css/dist/block-library/theme-rtl.css
  • wp-includes/css/dist/block-library/theme-rtl.min.css
  • wp-includes/css/dist/block-library/theme.css
  • wp-includes/css/dist/block-library/theme.min.css
  • wp-includes/css/dist/edit-post/classic-rtl.css
  • wp-includes/css/dist/edit-post/classic-rtl.min.css
  • wp-includes/css/dist/edit-post/classic.css
  • wp-includes/css/dist/edit-post/classic.min.css
  • wp-includes/css/dist/edit-post/style-rtl.css
  • wp-includes/css/dist/edit-post/style-rtl.min.css
  • wp-includes/css/dist/edit-post/style.css
  • wp-includes/css/dist/edit-post/style.min.css
  • wp-includes/css/dist/edit-site/style-rtl.css
  • wp-includes/css/dist/edit-site/style-rtl.min.css
  • wp-includes/css/dist/edit-site/style.css
  • wp-includes/css/dist/edit-site/style.min.css
  • wp-includes/css/dist/edit-widgets/style-rtl.css
  • wp-includes/css/dist/edit-widgets/style-rtl.min.css
  • wp-includes/css/dist/edit-widgets/style.css
  • wp-includes/css/dist/edit-widgets/style.min.css
  • wp-includes/css/dist/format-library/style-rtl.css
  • wp-includes/css/dist/format-library/style-rtl.min.css
  • wp-includes/css/dist/format-library/style.css
  • wp-includes/css/dist/format-library/style.min.css
  • wp-includes/css/dist/patterns/style-rtl.css
  • wp-includes/css/dist/patterns/style-rtl.min.css
  • wp-includes/css/dist/patterns/style.css
  • wp-includes/css/dist/patterns/style.min.css
  • wp-includes/css/dist/widgets/style-rtl.css
  • wp-includes/css/dist/widgets/style-rtl.min.css
  • wp-includes/css/dist/widgets/style.min.css
Check whether these files belong to the intended installation; source checkouts and partial deployments may omit files from the full distribution.
CMS_INTEGRITY_LIST_TRUNCATED (1)
wordpress:wp: 295 file(s) are listed in the official WordPress 6.4.2 distribution reference but absent from the scanned tree; the report lists the first 100
CMS_PROVIDER_UNCONFIGURED (1)
wordpress:wp — advisories (wordfence-v3): not-run — 1 component(s) not evaluated (CMS_PROVIDER_UNCONFIGURED). Configure the advisory source or import an authorized snapshot.
  • wordpress:wp

Application components (281)

ApplicationComponentVersionVisibilityPath
symfony · symfony-demolibrary · dflydev/dot-access-data3.0.2unknown?
symfony · symfony-demolibrary · doctrine/cache2.2.0unknown?
symfony · symfony-demolibrary · doctrine/dbal4.0.2unknown?
symfony · symfony-demolibrary · doctrine/deprecations1.1.3unknown?
symfony · symfony-demolibrary · doctrine/event-manager2.0.1unknown?
symfony · symfony-demolibrary · doctrine/inflector2.0.10unknown?
symfony · symfony-demolibrary · doctrine/lexer3.0.1unknown?
symfony · symfony-demolibrary · egulias/email-validator4.0.2unknown?
symfony · symfony-demolibrary · league/commonmark2.4.2unknown?
symfony · symfony-demolibrary · league/config1.2.0unknown?
symfony · symfony-demolibrary · masterminds/html52.9.0unknown?
symfony · symfony-demolibrary · monolog/monolog3.6.0unknown?
symfony · symfony-demolibrary · nette/schema1.3.0unknown?
symfony · symfony-demolibrary · nette/utils4.0.4unknown?
symfony · symfony-demolibrary · nikic/php-parser5.0.2unknown?
symfony · symfony-demolibrary · psr/cache3.0.0unknown?
symfony · symfony-demolibrary · psr/clock1.0.0unknown?
symfony · symfony-demolibrary · psr/container2.0.2unknown?
symfony · symfony-demolibrary · psr/event-dispatcher1.0.0unknown?
symfony · symfony-demolibrary · psr/http-factory1.1.0unknown?
symfony · symfony-demolibrary · psr/http-message2.0unknown?
symfony · symfony-demolibrary · psr/log3.0.0unknown?
symfony · symfony-demoframework-component · symfony/console7.1.1unknown?
symfony · symfony-demoframework-component · symfony/css-selector7.1.1unknown?
symfony · symfony-demolibrary · symfony/deprecation-contracts3.5.0unknown?
symfony · symfony-demoframework-component · symfony/error-handler7.1.1unknown?
symfony · symfony-demoframework-component · symfony/event-dispatcher7.1.1unknown?
symfony · symfony-demolibrary · symfony/event-dispatcher-contracts3.5.0unknown?
symfony · symfony-demoframework-component · symfony/finder7.1.1unknown?
symfony · symfony-demoframework-component · symfony/http-foundation7.1.1unknown?
symfony · symfony-demoframework-component · symfony/http-kernel7.1.1unknown?
symfony · symfony-demoframework-component · symfony/mime7.1.1unknown?
symfony · symfony-demolibrary · symfony/polyfill-ctype1.29.0unknown?
symfony · symfony-demolibrary · symfony/polyfill-intl-grapheme1.29.0unknown?
symfony · symfony-demolibrary · symfony/polyfill-intl-idn1.29.0unknown?
symfony · symfony-demolibrary · symfony/polyfill-intl-normalizer1.29.0unknown?
symfony · symfony-demolibrary · symfony/polyfill-mbstring1.29.0unknown?
symfony · symfony-demolibrary · symfony/polyfill-php831.29.0unknown?
symfony · symfony-demoframework-component · symfony/process7.1.1unknown?
symfony · symfony-demoframework-component · symfony/routing7.1.1unknown?
symfony · symfony-demolibrary · symfony/service-contracts3.5.0unknown?
symfony · symfony-demoframework-component · symfony/string7.1.1unknown?
symfony · symfony-demoframework-component · symfony/translation7.1.1unknown?
symfony · symfony-demolibrary · symfony/translation-contracts3.5.0unknown?
symfony · symfony-demoframework-component · symfony/var-dumper7.1.1unknown?
symfony · symfony-demolibrary · phpstan/phpstan1.11.3unknown?
symfony · symfony-demoframework-component · symfony/dom-crawler7.1.1unknown?
symfony · symfony-demolibrary · composer/semver3.4.0unknown?
symfony · symfony-demolibrary · doctrine/collections2.2.2unknown?
symfony · symfony-demoframework-component · symfony/dependency-injection7.1.1unknown?
symfony · symfony-demoframework-component · symfony/validator7.1.1unknown?
symfony · symfony-demoframework-component · symfony/yaml7.1.1unknown?
symfony · symfony-demolibrary · twig/twig3.10.3unknown?
symfony · symfony-demolibrary · doctrine/instantiator2.0.0unknown?
symfony · symfony-demoframework-component · symfony/browser-kit7.1.1unknown?
symfony · symfony-demolibrary · symfony/phpunit-bridge7.1.1unknown?
symfony · symfony-demobundle · doctrine/doctrine-bundle2.12.0unknown?
symfony · symfony-demobundle · doctrine/doctrine-migrations-bundle3.3.1unknown?
symfony · symfony-demolibrary · doctrine/migrations3.7.4unknown?
symfony · symfony-demolibrary · doctrine/orm3.2.0unknown?
symfony · symfony-demolibrary · doctrine/persistence3.3.2unknown?
symfony · symfony-demolibrary · doctrine/sql-formatter1.4.0unknown?
symfony · symfony-demolibrary · league/uri7.4.1unknown?
symfony · symfony-demolibrary · league/uri-interfaces7.4.1unknown?
symfony · symfony-demolibrary · symfony/apache-pack1.0.1unknown?
symfony · symfony-demoframework-component · symfony/asset7.1.1unknown?
symfony · symfony-demoframework-component · symfony/asset-mapper7.1.1unknown?
symfony · symfony-demoframework-component · symfony/cache7.1.1unknown?
symfony · symfony-demolibrary · symfony/cache-contracts3.5.0unknown?
symfony · symfony-demoframework-component · symfony/clock7.1.1unknown?
symfony · symfony-demoframework-component · symfony/config7.1.1unknown?
symfony · symfony-demoframework-component · symfony/doctrine-bridge7.1.1unknown?
symfony · symfony-demoframework-component · symfony/dotenv7.1.1unknown?
symfony · symfony-demoframework-component · symfony/expression-language7.1.1unknown?
symfony · symfony-demoframework-component · symfony/filesystem7.1.1unknown?
symfony · symfony-demolibrary · symfony/flex2.4.5unknown?
symfony · symfony-demoframework-component · symfony/form7.1.1unknown?
symfony · symfony-demoframework · symfony/framework-bundle7.1.1unknown?
symfony · symfony-demolibrary · symfony/html-sanitizer7.1.1unknown?
symfony · symfony-demoframework-component · symfony/http-client7.1.1unknown?
symfony · symfony-demolibrary · symfony/http-client-contracts3.5.0unknown?
symfony · symfony-demoframework-component · symfony/intl7.1.1unknown?
symfony · symfony-demoframework-component · symfony/mailer7.1.1unknown?
symfony · symfony-demoframework-component · symfony/monolog-bridge7.1.1unknown?
symfony · symfony-demobundle · symfony/monolog-bundle3.10.0unknown?
symfony · symfony-demoframework-component · symfony/options-resolver7.1.1unknown?
symfony · symfony-demoframework-component · symfony/password-hasher7.1.1unknown?
symfony · symfony-demolibrary · symfony/polyfill-intl-icu1.29.0unknown?
symfony · symfony-demolibrary · symfony/polyfill-intl-messageformatter1.29.0unknown?
symfony · symfony-demoframework-component · symfony/property-access7.1.1unknown?
symfony · symfony-demoframework-component · symfony/property-info7.1.1unknown?
symfony · symfony-demolibrary · symfony/runtime7.1.1unknown?
symfony · symfony-demoframework-component · symfony/security-bundle7.1.1unknown?
symfony · symfony-demoframework-component · symfony/security-core7.1.1unknown?
symfony · symfony-demoframework-component · symfony/security-csrf7.1.1unknown?
symfony · symfony-demoframework-component · symfony/security-http7.1.1unknown?
symfony · symfony-demobundle · symfony/stimulus-bundle2.17.0unknown?
symfony · symfony-demoframework-component · symfony/stopwatch7.1.1unknown?
symfony · symfony-demoframework-component · symfony/twig-bridge7.1.1unknown?
symfony · symfony-demoframework-component · symfony/twig-bundle7.1.1unknown?
symfony · symfony-demoframework-component · symfony/type-info7.1.1unknown?
symfony · symfony-demolibrary · symfony/ux-live-component2.17.0unknown?
symfony · symfony-demolibrary · symfony/ux-twig-component2.17.0unknown?
symfony · symfony-demoframework-component · symfony/var-exporter7.1.1unknown?
symfony · symfony-demobundle · symfonycasts/sass-bundle0.3.0unknown?
symfony · symfony-demobundle · twig/extra-bundle3.10.0unknown?
symfony · symfony-demolibrary · twig/intl-extra3.10.0unknown?
symfony · symfony-demolibrary · twig/markdown-extra3.10.0unknown?
symfony · symfony-demobundle · dama/doctrine-test-bundle8.2.0unknown?
symfony · symfony-demolibrary · doctrine/data-fixtures1.7.0unknown?
symfony · symfony-demobundle · doctrine/doctrine-fixtures-bundle3.6.1unknown?
symfony · symfony-demolibrary · phpstan/extension-installer1.3.1unknown?
symfony · symfony-demolibrary · phpstan/phpstan-doctrine1.4.1unknown?
symfony · symfony-demolibrary · phpstan/phpstan-symfony1.4.3unknown?
symfony · symfony-demoframework-component · symfony/debug-bundle7.1.1unknown?
symfony · symfony-demobundle · symfony/maker-bundle1.59.1unknown?
symfony · symfony-demoframework-component · symfony/web-profiler-bundle7.1.1unknown?
symfony · symfony-demolibrary · twbs/bootstrap4.6.2unknown?
wordpress · wpcore · WordPress6.4.2publicwp
wordpress · wptheme · Twenty Eleven4.5unknownwp/wp-content/themes/twentyeleven
wordpress · wptheme · Twenty Fifteen3.6unknownwp/wp-content/themes/twentyfifteen
wordpress · wptheme · Twenty Fourteen3.8unknownwp/wp-content/themes/twentyfourteen
wordpress · wptheme · Twenty Nineteen2.7unknownwp/wp-content/themes/twentynineteen
wordpress · wptheme · Twenty Seventeen3.4unknownwp/wp-content/themes/twentyseventeen
wordpress · wptheme · Twenty Sixteen3.1unknownwp/wp-content/themes/twentysixteen
wordpress · wptheme · Twenty Ten4.0unknownwp/wp-content/themes/twentyten
wordpress · wptheme · Twenty Thirteen4.0unknownwp/wp-content/themes/twentythirteen
wordpress · wptheme · Twenty Twelve4.1unknownwp/wp-content/themes/twentytwelve
wordpress · wptheme · Twenty Twenty2.4unknownwp/wp-content/themes/twentytwenty
wordpress · wptheme · Twenty Twenty-Four1.0unknownwp/wp-content/themes/twentytwentyfour
wordpress · wptheme · Twenty Twenty-One2.0unknownwp/wp-content/themes/twentytwentyone
wordpress · wptheme · Twenty Twenty-Three1.3unknownwp/wp-content/themes/twentytwentythree
wordpress · wptheme · Twenty Twenty-Two1.6unknownwp/wp-content/themes/twentytwentytwo
drupal · drupalcore · Drupal8.5.0publicdrupal
laravel · bookstacklibrary · aws/aws-crt-php1.2.6unknown?
laravel · bookstacklibrary · aws/aws-sdk-php3.322.6unknown?
laravel · bookstacklibrary · bacon/bacon-qr-code3.0.0unknown?
laravel · bookstacklibrary · brick/math0.12.1unknown?
laravel · bookstacklibrary · carbonphp/carbon-doctrine-types2.1.0unknown?
laravel · bookstacklibrary · dasprid/enum1.0.6unknown?
laravel · bookstacklibrary · dflydev/dot-access-data3.0.3unknown?
laravel · bookstacklibrary · doctrine/cache2.2.0unknown?
laravel · bookstacklibrary · doctrine/dbal3.9.1unknown?
laravel · bookstacklibrary · doctrine/deprecations1.1.3unknown?
laravel · bookstacklibrary · doctrine/event-manager2.0.1unknown?
laravel · bookstacklibrary · doctrine/inflector2.0.10unknown?
laravel · bookstacklibrary · doctrine/lexer3.0.1unknown?
laravel · bookstacklibrary · dompdf/dompdf3.0.0unknown?
laravel · bookstacklibrary · dompdf/php-font-lib1.0.0unknown?
laravel · bookstacklibrary · dompdf/php-svg-lib1.0.0unknown?
laravel · bookstacklibrary · dragonmantank/cron-expression3.3.3unknown?
laravel · bookstacklibrary · egulias/email-validator4.0.2unknown?
laravel · bookstacklibrary · firebase/php-jwt6.10.1unknown?
laravel · bookstacklibrary · fruitcake/php-cors1.3.0unknown?
laravel · bookstacklibrary · graham-campbell/result-type1.1.3unknown?
laravel · bookstacklibrary · guzzlehttp/guzzle7.9.2unknown?
laravel · bookstacklibrary · guzzlehttp/promises2.0.3unknown?
laravel · bookstacklibrary · guzzlehttp/psr72.7.0unknown?
laravel · bookstacklibrary · guzzlehttp/uri-template1.0.3unknown?
laravel · bookstacklibrary · intervention/gif4.2.0unknown?
laravel · bookstacklibrary · intervention/image3.8.0unknown?
laravel · bookstacklibrary · knplabs/knp-snappy1.5.0unknown?
laravel · bookstackframework · laravel/framework10.48.22unknown?
laravel · bookstackframework-component · laravel/prompts0.1.25unknown?
laravel · bookstackframework-component · laravel/serializable-closure1.3.5unknown?
laravel · bookstackframework-component · laravel/socialite5.16.0unknown?
laravel · bookstackframework-component · laravel/tinker2.10.0unknown?
laravel · bookstacklibrary · league/commonmark2.5.3unknown?
laravel · bookstacklibrary · league/config1.2.0unknown?
laravel · bookstacklibrary · league/flysystem3.28.0unknown?
laravel · bookstacklibrary · league/flysystem-aws-s3-v33.28.0unknown?
laravel · bookstacklibrary · league/flysystem-local3.28.0unknown?
laravel · bookstacklibrary · league/html-to-markdown5.1.1unknown?
laravel · bookstacklibrary · league/mime-type-detection1.16.0unknown?
laravel · bookstacklibrary · league/oauth1-client1.10.1unknown?
laravel · bookstacklibrary · league/oauth2-client2.7.0unknown?
laravel · bookstacklibrary · masterminds/html52.9.0unknown?
laravel · bookstacklibrary · monolog/monolog3.7.0unknown?
laravel · bookstacklibrary · mtdowling/jmespath.php2.8.0unknown?
laravel · bookstacklibrary · nesbot/carbon2.72.5unknown?
laravel · bookstacklibrary · nette/schema1.3.0unknown?
laravel · bookstacklibrary · nette/utils4.0.5unknown?
laravel · bookstacklibrary · nikic/php-parser5.2.0unknown?
laravel · bookstacklibrary · nunomaduro/termwind1.15.1unknown?
laravel · bookstacklibrary · onelogin/php-saml4.2.0unknown?
laravel · bookstacklibrary · paragonie/constant_time_encoding3.0.0unknown?
laravel · bookstacklibrary · paragonie/random_compat9.99.100unknown?
laravel · bookstacklibrary · phpoption/phpoption1.9.3unknown?
laravel · bookstacklibrary · phpseclib/phpseclib3.0.42unknown?
laravel · bookstacklibrary · pragmarx/google2fa8.0.3unknown?
laravel · bookstacklibrary · predis/predis2.2.2unknown?
laravel · bookstacklibrary · psr/cache3.0.0unknown?
laravel · bookstacklibrary · psr/clock1.0.0unknown?
laravel · bookstacklibrary · psr/container2.0.2unknown?
laravel · bookstacklibrary · psr/event-dispatcher1.0.0unknown?
laravel · bookstacklibrary · psr/http-client1.0.3unknown?
laravel · bookstacklibrary · psr/http-factory1.1.0unknown?
laravel · bookstacklibrary · psr/http-message2.0unknown?
laravel · bookstacklibrary · psr/log3.0.2unknown?
laravel · bookstacklibrary · psr/simple-cache3.0.0unknown?
laravel · bookstacklibrary · psy/psysh0.12.4unknown?
laravel · bookstacklibrary · ralouphie/getallheaders3.0.3unknown?
laravel · bookstacklibrary · ramsey/collection2.0.0unknown?
laravel · bookstacklibrary · ramsey/uuid4.7.6unknown?
laravel · bookstacklibrary · robrichards/xmlseclibs3.1.1unknown?
laravel · bookstacklibrary · sabberworm/php-css-parser8.6.0unknown?
laravel · bookstacklibrary · socialiteproviders/discord4.2.0unknown?
laravel · bookstacklibrary · socialiteproviders/gitlab4.1.0unknown?
laravel · bookstacklibrary · socialiteproviders/manager4.6.0unknown?
laravel · bookstacklibrary · socialiteproviders/microsoft-azure5.2.0unknown?
laravel · bookstacklibrary · socialiteproviders/okta4.4.0unknown?
laravel · bookstacklibrary · socialiteproviders/twitch5.4.0unknown?
laravel · bookstacklibrary · ssddanbrown/htmldiff1.0.3unknown?
laravel · bookstacklibrary · ssddanbrown/symfony-mailer6.4.x-devunknown?
laravel · bookstacklibrary · symfony/console6.4.12unknown?
laravel · bookstacklibrary · symfony/css-selector6.4.8unknown?
laravel · bookstacklibrary · symfony/deprecation-contracts3.5.0unknown?
laravel · bookstacklibrary · symfony/error-handler6.4.10unknown?
laravel · bookstacklibrary · symfony/event-dispatcher6.4.8unknown?
laravel · bookstacklibrary · symfony/event-dispatcher-contracts3.5.0unknown?
laravel · bookstacklibrary · symfony/finder6.4.11unknown?
laravel · bookstacklibrary · symfony/http-foundation6.4.12unknown?
laravel · bookstacklibrary · symfony/http-kernel6.4.12unknown?
laravel · bookstacklibrary · symfony/mime6.4.12unknown?
laravel · bookstacklibrary · symfony/polyfill-ctype1.31.0unknown?
laravel · bookstacklibrary · symfony/polyfill-intl-grapheme1.31.0unknown?
laravel · bookstacklibrary · symfony/polyfill-intl-idn1.31.0unknown?
laravel · bookstacklibrary · symfony/polyfill-intl-normalizer1.31.0unknown?
laravel · bookstacklibrary · symfony/polyfill-mbstring1.31.0unknown?
laravel · bookstacklibrary · symfony/polyfill-php801.31.0unknown?
laravel · bookstacklibrary · symfony/polyfill-php831.31.0unknown?
laravel · bookstacklibrary · symfony/polyfill-uuid1.31.0unknown?
laravel · bookstacklibrary · symfony/process6.4.12unknown?
laravel · bookstacklibrary · symfony/routing6.4.12unknown?
laravel · bookstacklibrary · symfony/service-contracts3.5.0unknown?
laravel · bookstacklibrary · symfony/string6.4.12unknown?
laravel · bookstacklibrary · symfony/translation6.4.12unknown?
laravel · bookstacklibrary · symfony/translation-contracts3.5.0unknown?
laravel · bookstacklibrary · symfony/uid6.4.12unknown?
laravel · bookstacklibrary · symfony/var-dumper6.4.11unknown?
laravel · bookstacklibrary · tijsverkoyen/css-to-inline-styles2.2.7unknown?
laravel · bookstacklibrary · vlucas/phpdotenv5.6.1unknown?
laravel · bookstacklibrary · voku/portable-ascii2.0.1unknown?
laravel · bookstacklibrary · webmozart/assert1.11.0unknown?
laravel · bookstacklibrary · fakerphp/faker1.23.1unknown?
laravel · bookstacklibrary · filp/whoops2.16.0unknown?
laravel · bookstacklibrary · hamcrest/hamcrest-php2.0.1unknown?
laravel · bookstacklibrary · itsgoingd/clockwork5.2.2unknown?
laravel · bookstacklibrary · larastan/larastan2.9.8unknown?
laravel · bookstacklibrary · mockery/mockery1.6.12unknown?
laravel · bookstacklibrary · myclabs/deep-copy1.12.0unknown?
laravel · bookstacklibrary · nunomaduro/collision7.10.0unknown?
laravel · bookstacklibrary · phar-io/manifest2.0.4unknown?
laravel · bookstacklibrary · phar-io/version3.2.1unknown?
laravel · bookstacklibrary · phpmyadmin/sql-parser5.10.0unknown?
laravel · bookstacklibrary · phpstan/phpstan1.12.5unknown?
laravel · bookstacklibrary · phpunit/php-code-coverage10.1.16unknown?
laravel · bookstacklibrary · phpunit/php-file-iterator4.1.0unknown?
laravel · bookstacklibrary · phpunit/php-invoker4.0.0unknown?
laravel · bookstacklibrary · phpunit/php-text-template3.0.1unknown?
laravel · bookstacklibrary · phpunit/php-timer6.0.0unknown?
laravel · bookstacklibrary · phpunit/phpunit10.5.35unknown?
laravel · bookstacklibrary · sebastian/cli-parser2.0.1unknown?
laravel · bookstacklibrary · sebastian/code-unit2.0.0unknown?
laravel · bookstacklibrary · sebastian/code-unit-reverse-lookup3.0.0unknown?
laravel · bookstacklibrary · sebastian/comparator5.0.2unknown?
laravel · bookstacklibrary · sebastian/complexity3.2.0unknown?
laravel · bookstacklibrary · sebastian/diff5.1.1unknown?
laravel · bookstacklibrary · sebastian/environment6.1.0unknown?
laravel · bookstacklibrary · sebastian/exporter5.1.2unknown?
laravel · bookstacklibrary · sebastian/global-state6.0.2unknown?
laravel · bookstacklibrary · sebastian/lines-of-code2.0.2unknown?
laravel · bookstacklibrary · sebastian/object-enumerator5.0.0unknown?
laravel · bookstacklibrary · sebastian/object-reflector3.0.0unknown?
laravel · bookstacklibrary · sebastian/recursion-context5.0.0unknown?
laravel · bookstacklibrary · sebastian/type4.0.0unknown?
laravel · bookstacklibrary · sebastian/version4.0.1unknown?
laravel · bookstacklibrary · squizlabs/php_codesniffer3.10.3unknown?
laravel · bookstacklibrary · ssddanbrown/asserthtml3.0.0unknown?
laravel · bookstacklibrary · symfony/dom-crawler6.4.12unknown?
laravel · bookstacklibrary · theseer/tokenizer1.2.3unknown?

Application coverage (10)

ApplicationCapability / sourceComponentExecutionResultCheckedDiagnostic
symfony:symfony-demoinventory—completednot-applicable118/118—
symfony:symfony-demoadvisories · dependency-lanes—completednot-applicable118/118—
symfony:symfony-demorecipes—completednot-applicable110/110—
wordpress:wpinventory—completednot-applicable15/15—
wordpress:wpadvisories · wordfence-v3—not-runindeterminate0/15CMS_PROVIDER_UNCONFIGURED
wordpress:wpintegrity · wordpress-checksums—completedno-match2960/2960—
drupal:drupalinventory—completednot-applicable1/1—
drupal:drupaladvisories · drupal-security-advisoriescore · Drupal
drupal
drupal:drupal:core
completedaffected1/1—
laravel:bookstackinventory—completednot-applicable147/147—
laravel:bookstackadvisories · dependency-lanes—completednot-applicable147/147—