CVE Tools

Symfony/http-foundation

13 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Symfony/http-foundation, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Symfony/http-foundation CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Symfony/http-foundation CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical111%
  • High222%
  • Medium444%
  • Low222%

Latest CVEs

The 13 most recently published vulnerabilities affecting Symfony/http-foundation.

  1. CVE-2025-64500Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass7.3
  2. CVE-2024-50345Open redirect via browser-sanitized URLs in symfony/http-foundation3.1
  3. CVE-2015-2309Symfony has unsafe methods in the Request class—
  4. CVE-2014-6061Symfony has a security issue when parsing the Authorization header—
  5. CVE-2014-5244Symfony vulnerable to denial of service via a malicious HTTP Host header—
  6. GHSA-vfm6-r2gc-pwwwSymfony2 security issue when the trust proxy mode is enabled—
  7. CVE-2020-5255Prevent cache poisoning via a Response Content-Type header2.6
  8. CVE-2013-4752Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when th...6.1
  9. CVE-2019-18888An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which M...7.5
  10. CVE-2019-10913In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted in...9.8
  11. CVE-2018-14773An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arise...6.5
  12. CVE-2018-11386An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler...5.9
  13. CVE-2012-6431Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly...6.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store