MEDIUM5.9Packagist
GHSA-pjhx-3c3w-9v23· CVE-2026-49858API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
Modified: 7/10/2026
package
pkg:packagist/api-platform/json-api
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
Modified: 7/10/2026