LOW3.1
GHSA-g3rh-rrhp-jhh9
Symfony has an incorrect response from Validator when input ends with `\n`
Quick fix
GHSA-g3rh-rrhp-jhh9 — symfony/symfony: upgrade to the fixed version with the command below.
composer require symfony/symfony:^5.4.43Details
### Description
It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`.
### Resolution
Symfony now uses the `D` regex modifier to match the entire input.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/7d1032bbead9a4229b32fa6ebca32681c80cb76f) for branch 5.4.
### Credits
We would like to thank Offscript for reporting the issue and Alexandre Daubois for providing the fix.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/symfony
Introduced in:
0Fixed in: 5.4.43Fix
composer require symfony/symfony:^5.4.43Packagist/symfony/symfony
Introduced in:
6.0.0Fixed in: 6.4.11Fix
composer require symfony/symfony:^6.4.11Packagist/symfony/symfony
Introduced in:
7.0.0Fixed in: 7.1.4Fix
composer require symfony/symfony:^7.1.4Packagist/symfony/validator
Introduced in:
0Fixed in: 5.4.43Fix
composer require symfony/validator:^5.4.43Packagist/symfony/validator
Introduced in:
6.0.0Fixed in: 6.4.11Fix
composer require symfony/validator:^6.4.11Packagist/symfony/validator
Introduced in:
7.0.0Fixed in: 7.1.4Fix
composer require symfony/validator:^7.1.4References
- https://github.com/symfony/symfony/security/advisories/GHSA-g3rh-rrhp-jhh9[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-50343[ADVISORY]
- https://github.com/symfony/symfony/commit/7d1032bbead9a4229b32fa6ebca32681c80cb76f[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2024-50343.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/validator/CVE-2024-50343.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2025/05/msg00051.html[WEB]
- https://symfony.com/cve-2024-50343[WEB]