Missing Authentication for Critical Function Affecting symfony/twilio-notifier package, versions >=6.4.0-BETA1, <6.4.40>=7.0.0-BETA1, <7.4.12>=8.0.0-BETA1, <8.0.12


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.24% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authentication for Critical Function vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-SYMFONYTWILIONOTIFIER-16873900
  • published24 May 2026
  • disclosed20 May 2026
  • creditHimanshu Anand

Introduced: 20 May 2026

CVE-2026-47212  (opens in a new tab)
CWE-306  (opens in a new tab)

How to fix?

Upgrade symfony/twilio-notifier to version 6.4.40, 7.4.12, 8.0.12 or higher.

Overview

symfony/twilio-notifier is a Symfony Twilio Notifier Bridge

Affected versions of this package are vulnerable to Missing Authentication for Critical Function via the doParse() webhook request parser in the notifier bridge. An attacker can submit forged webhook status events because the parser ignores the X-Twilio-Signature HMAC header and never validates the configured webhook secret, allowing unauthenticated POST requests to be processed as legitimate Twilio callbacks. This can lead to falsified delivered, failed, or undelivered events, resulting in delivery-metrics manipulation or unintended downstream automation triggers.

CVSS Base Scores

version 4.0
version 3.1