symfony/http-foundation vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the symfony/http-foundation package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Open Redirect

<5.4.46>=6.0.0-BETA1, <6.4.14>=7.0.0-BETA1, <7.1.7
  • L
Denial of Service

>=4.4.0, <4.4.7>=5.0.0, <5.0.7
  • H
Arbitrary Code Execution

>=2.8.0, <2.8.52>=3.4.0, <3.4.35>=4.2.0, <4.2.11>=4.3.0, <4.3.8
  • M
Improper Input Validation

>=4.2.0, <4.2.7
  • H
Host Header Injection

<2.7.49>=2.8.0, <2.8.44>=3.3.0, <3.3.18>=3.4.0, <3.4.14>=4.0.0, <4.0.14>=4.1.0, <4.1.2
  • M
Access Restriction Bypass

>=2.7, <2.7.49>=2.8, <2.8.44>=3.0.0, <3.3.18>=3.4, <3.4.14>=4.0.0, <4.0.14>=4.1, <4.1.3
  • M
Denial of Service (DoS)

<2.7.48>=2.8.0, <2.8.41>=3.0.0, <3.3.17>=3.4.0, <3.4.11>=4.0.0, <4.0.11
  • M
Man-in-the-Middle (MitM)

>=2.0.0, <2.3.27>=2.4.0, <2.5.11>=2.6.0, <2.6.6
  • L
Authentication Bypass

>=2.3.0, <2.3.19>=2.1.0, <2.2.0>=2.4.0, <2.4.9>=2.5.0, <2.5.4>=2.2.0, <2.3.0>=2.0.0, <2.1.0
  • M
Denial of Service (DoS)

>=2.0.0, <2.3.19>=2.4.0, <2.4.9>=2.5.0, <2.5.4
  • M
Denial of Service (DoS)

>=2.0.4, <2.3.19>=2.4.0, <2.4.9>=2.5.0, <2.5.4
  • H
HTTP Host Header Poisoning

>=2.3.0, <2.3.3>=2.1.0, <2.1.12>=2.2.0, <2.2.5>=2.0.0, <2.0.24
  • M
Access Restriction Bypass

>=2.1.0, <2.1.4>=2.0.0, <2.0.19
  • M
Access Restriction Bypass

>=2.1.0, <2.1.4>=2.0.0, <2.0.19
  • M
Path Disclosure

>=2.0.0, <2.0.19