LOWPackagist
GHSA-34w5-c283-j9fg· CVE-2026-49212symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Modified: 9/10/2026
package
pkg:packagist/symfony/ux-live-component
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Modified: 9/10/2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Modified: 9/10/2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Modified: 9/10/2026
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
Modified: 8/29/2025
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Modified: 9/10/2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Modified: 9/10/2026