icon

We found results for “

CVE-2025-64500

Good to know:

icon
icon

Date: November 12, 2025

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the "Request" class improperly interprets some "PATH_INFO" in a way that leads to representing some URLs with a path that doesn't start with a "/". This can allow bypassing some access control rules that are built with this "/"-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the "Request" class now ensures that URL paths always start with a "/".

Severity Score

Severity Score

Weakness Type (CWE)

Use of Non-Canonical URL Paths for Authorization Decisions

CWE-647

Top Fix

icon

Upgrade Version

Upgrade to version symfony/symfony - v5.4.50;symfony/symfony - v6.4.29;symfony/symfony - v7.3.7;symfony/http-foundation - v5.4.50;symfony/http-foundation - v6.4.29;symfony/http-foundation - v7.3.7

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us