GHSA-3rg7-wf37-54rm
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
Quick fix
GHSA-3rg7-wf37-54rm — symfony/http-foundation: upgrade to the fixed version with the command below.
composer require symfony/http-foundation:^5.4.50Details
### Description
The `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption.
### Resolution
The `Request` class now ensures that URL paths always start with a `/`.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/9962b91b12bb791322fa73836b350836b6db7cac) for branch 5.4.
### Credits
We would like to thank Andrew Atkinson for discovering the issue, Chris Smith for reporting it and Nicolas Grekas for providing the fix.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 5.4.50composer require symfony/http-foundation:^5.4.506.0.0Fixed in: 6.4.29composer require symfony/http-foundation:^6.4.297.0.0Fixed in: 7.3.7composer require symfony/http-foundation:^7.3.72.0.0Fixed in: 5.4.50composer require symfony/symfony:^5.4.506.0.0Fixed in: 6.4.29composer require symfony/symfony:^6.4.297.0.0Fixed in: 7.3.7composer require symfony/symfony:^7.3.7References
- https://github.com/symfony/symfony/security/advisories/GHSA-3rg7-wf37-54rm[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-64500[ADVISORY]
- https://github.com/symfony/symfony/commit/9962b91b12bb791322fa73836b350836b6db7cac[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-foundation/CVE-2025-64500.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2025-64500.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://symfony.com/blog/cve-2025-64500-incorrect-parsing-of-path-info-can-lead-to-limited-authorization-bypass[WEB]