CVE-2026-45069
CVE-2026-45069
8.8
HighPublished:
Last updated:
Source:security-advisories@github.com
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- Low
- Availability (Vulnerable)
- None
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
References
security-advisories@github.com
https://github.com/symfony/symfony/releases/tag/v6.4.40security-advisories@github.com
https://github.com/symfony/symfony/releases/tag/v7.4.12security-advisories@github.com
https://github.com/symfony/symfony/releases/tag/v8.0.12security-advisories@github.com
https://github.com/symfony/symfony/security/advisories/GHSA-29fc-p6c4-24cg