CVE-2026-45077
CVE-2026-45077
8.3
HighPublished:
Last updated:
Source:security-advisories@github.com
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- Present
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- Low
- Integrity (Vulnerable)
- Low
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with unserialize(base64_decode($message)) without authentication, integrity checks, or an allowed_classes allowlist, allowing any reachable host to submit attacker-chosen serialized PHP payloads that can crash the listener and may trigger object-injection gadget effects. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
References
security-advisories@github.com
https://github.com/symfony/symfony/commit/0891b2f293896c488e26943dc034334364b77fc4security-advisories@github.com
https://github.com/symfony/symfony/releases/tag/v5.4.52security-advisories@github.com
https://github.com/symfony/symfony/releases/tag/v6.4.40security-advisories@github.com
https://github.com/symfony/symfony/releases/tag/v7.4.12security-advisories@github.com
https://github.com/symfony/symfony/releases/tag/v8.0.12security-advisories@github.com
https://github.com/symfony/symfony/security/advisories/GHSA-m7v2-7gxm-vc2v