symfony/http-foundation vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the symfony/http-foundation package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Open Redirect

<5.4.46 >=6.0.0-BETA1, <6.4.14 >=7.0.0-BETA1, <7.1.7
  • L
Denial of Service

>=4.4.0, <4.4.7 >=5.0.0, <5.0.7
  • H
Arbitrary Code Execution

>=2.8.0, <2.8.52 >=3.4.0, <3.4.35 >=4.2.0, <4.2.11 >=4.3.0, <4.3.8
  • M
Improper Input Validation

>=4.2.0, <4.2.7
  • H
Host Header Injection

<2.7.49 >=2.8.0, <2.8.44 >=3.3.0, <3.3.18 >=3.4.0, <3.4.14 >=4.0.0, <4.0.14 >=4.1.0, <4.1.2
  • M
Access Restriction Bypass

>=2.7, <2.7.49 >=2.8, <2.8.44 >=3.0.0, <3.3.18 >=3.4, <3.4.14 >=4.0.0, <4.0.14 >=4.1, <4.1.3
  • M
Denial of Service (DoS)

<2.7.48 >=2.8.0, <2.8.41 >=3.0.0, <3.3.17 >=3.4.0, <3.4.11 >=4.0.0, <4.0.11
  • M
Man-in-the-Middle (MitM)

>=2.0.0, <2.3.27 >=2.4.0, <2.5.11 >=2.6.0, <2.6.6
  • L
Authentication Bypass

>=2.3.0, <2.3.19 >=2.1.0, <2.2.0 >=2.4.0, <2.4.9 >=2.5.0, <2.5.4 >=2.2.0, <2.3.0 >=2.0.0, <2.1.0
  • M
Denial of Service (DoS)

>=2.0.4, <2.3.19 >=2.4.0, <2.4.9 >=2.5.0, <2.5.4
  • M
Denial of Service (DoS)

>=2.0.0, <2.3.19 >=2.4.0, <2.4.9 >=2.5.0, <2.5.4
  • H
HTTP Host Header Poisoning

>=2.3.0, <2.3.3 >=2.1.0, <2.1.12 >=2.2.0, <2.2.5 >=2.0.0, <2.0.24
  • M
Access Restriction Bypass

>=2.1.0, <2.1.4 >=2.0.0, <2.0.19
  • M
Access Restriction Bypass

>=2.1.0, <2.1.4 >=2.0.0, <2.0.19
  • M
Path Disclosure

>=2.0.0, <2.0.19