Symfony/security-http
16 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Symfony/security-http, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Symfony/security-http CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 2 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High8
- Medium7
Latest CVEs
The 15 most recently published vulnerabilities affecting Symfony/security-http.
- CVE-2024-36611In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request...7.5
- CVE-2024-51996Symphony has an Authentication Bypass via RememberMe7.5
- CVE-2023-46733Symfony possible session fixation vulnerability6.5
- CVE-2021-32693Authentication granted with multiple firewalls6.8
- GHSA-g2qj-pmxm-9f8fUser enumeration in authentication mechanisms—
- CVE-2021-21424Prevent user enumeration using Guard or the new Authenticator-based Security5.3
- CVE-2020-5275Firewall configured with unanimous strategy was not actually unanimous in symfony/security-http7.6
- CVE-2019-18886An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauth...5.3
- CVE-2019-10911In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites wi...7.5
- CVE-2018-19790An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `...6.1
- CVE-2018-11406An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's sessio...8.8
- CVE-2018-11385An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerab...8.1
- CVE-2017-16652An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler...6.1
- CVE-2016-4423The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x be...7.5
- CVE-2015-8124Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a se...6.8
Product grouping is registry-driven, with AI assist and human review. How it works