Symfony Host Header Injection vulnerability in the HttpFoundation component
Modified: 3/16/2024
package
pkg:packagist/symfony/http-foundation
Symfony Host Header Injection vulnerability in the HttpFoundation component
Modified: 3/16/2024
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Modified: 9/10/2026
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
Modified: 9/10/2026
Symfony Allows URI Restrictions Bypass Via Double-Encoded String
Modified: 12/3/2024
Symfony HTTP Foundation web cache poisoning
Modified: 2/16/2024
Symfony has a security issue when parsing the Authorization header
Modified: 5/30/2024
Prevent cache poisoning via a Response Content-Type header in Symfony
Modified: 9/10/2026
Symfony vulnerable to open redirect via browser-sanitized URLs
Modified: 11/3/2025
Symfony has unsafe methods in the Request class
Modified: 5/30/2024
Symfony DoS
Modified: 2/17/2024
Symfony vulnerable to denial of service via a malicious HTTP Host header
Modified: 5/30/2024
Symfony2 security issue when the trust proxy mode is enabled
Modified: 12/4/2024
Invalid HTTP method overrides allow possible XSS or other attacks in Symfony
Modified: 11/8/2023
Argument injection in a MimeTypeGuesser in Symfony
Modified: 2/20/2024