Debian Package Tracker
Register | Log in
Subscribe

symfony

Choose email to subscribe with

general
  • source: symfony (main)
  • version: 7.4.14+dfsg-1
  • maintainer: Debian PHP PEAR Maintainers (archive) (DMD)
  • uploaders: David Prévot [DMD] – Daniel Beyer [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 4.4.19+dfsg-2+deb11u6
  • o-o-sec: 4.4.19+dfsg-2+deb11u7
  • o-o-p-u: 4.4.19+dfsg-2+deb11u6
  • oldstable: 5.4.53+dfsg-0+deb12u1
  • old-sec: 5.4.53+dfsg-0+deb12u1
  • old-p-u: 5.4.53+dfsg-0+deb12u1
  • stable: 6.4.41+dfsg-0+deb13u1
  • stable-sec: 6.4.41+dfsg-0+deb13u1
  • testing: 7.4.14+dfsg-1
  • unstable: 7.4.14+dfsg-1
  • exp: 8.1.1+dfsg-1
versioned links
  • 4.4.19+dfsg-2+deb11u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.4.19+dfsg-2+deb11u7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.4.53+dfsg-0+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.4.41+dfsg-0+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 7.4.14+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 8.1.0+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 8.1.1+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • php-symfony
  • php-symfony-aha-send-mailer
  • php-symfony-all-my-sms-notifier
  • php-symfony-amazon-dynamo-db-lock
  • php-symfony-amazon-mailer
  • php-symfony-amazon-sns-notifier
  • php-symfony-amazon-sqs-messenger
  • php-symfony-amqp-messenger
  • php-symfony-asset
  • php-symfony-asset-mapper
  • php-symfony-azure-mailer
  • php-symfony-bandwidth-notifier
  • php-symfony-beanstalkd-messenger
  • php-symfony-bluesky-notifier
  • php-symfony-brevo-mailer
  • php-symfony-brevo-notifier
  • php-symfony-browser-kit
  • php-symfony-cache
  • php-symfony-chatwork-notifier
  • php-symfony-click-send-notifier
  • php-symfony-clickatell-notifier
  • php-symfony-clock
  • php-symfony-config
  • php-symfony-console
  • php-symfony-contact-everyone-notifier
  • php-symfony-crowdin-translation-provider
  • php-symfony-css-selector
  • php-symfony-debug-bundle
  • php-symfony-dependency-injection
  • php-symfony-discord-notifier
  • php-symfony-doctrine-bridge
  • php-symfony-doctrine-messenger
  • php-symfony-dom-crawler
  • php-symfony-dotenv
  • php-symfony-emoji
  • php-symfony-engagespot-notifier
  • php-symfony-error-handler
  • php-symfony-esendex-notifier
  • php-symfony-event-dispatcher (1 bugs: 0, 1, 0, 0)
  • php-symfony-expo-notifier
  • php-symfony-expression-language
  • php-symfony-fake-chat-notifier
  • php-symfony-fake-sms-notifier
  • php-symfony-filesystem
  • php-symfony-finder
  • php-symfony-firebase-notifier
  • php-symfony-form
  • php-symfony-forty-six-elks-notifier
  • php-symfony-framework-bundle
  • php-symfony-free-mobile-notifier
  • php-symfony-gateway-api-notifier
  • php-symfony-go-ip-notifier
  • php-symfony-google-chat-notifier
  • php-symfony-google-mailer
  • php-symfony-html-sanitizer
  • php-symfony-http-client
  • php-symfony-http-foundation
  • php-symfony-http-kernel
  • php-symfony-infobip-mailer
  • php-symfony-infobip-notifier
  • php-symfony-intl
  • php-symfony-iqsms-notifier
  • php-symfony-isendpro-notifier
  • php-symfony-joli-notif-notifier
  • php-symfony-json-path
  • php-symfony-json-streamer
  • php-symfony-kaz-info-teh-notifier
  • php-symfony-ldap
  • php-symfony-light-sms-notifier
  • php-symfony-line-bot-notifier
  • php-symfony-line-notify-notifier
  • php-symfony-linked-in-notifier
  • php-symfony-lock
  • php-symfony-loco-translation-provider
  • php-symfony-lokalise-translation-provider
  • php-symfony-lox24-notifier
  • php-symfony-mail-pace-mailer
  • php-symfony-mailchimp-mailer
  • php-symfony-mailer
  • php-symfony-mailer-send-mailer
  • php-symfony-mailgun-mailer
  • php-symfony-mailjet-mailer
  • php-symfony-mailjet-notifier
  • php-symfony-mailomat-mailer
  • php-symfony-mailtrap-mailer
  • php-symfony-mastodon-notifier
  • php-symfony-matrix-notifier
  • php-symfony-mattermost-notifier
  • php-symfony-mercure-notifier
  • php-symfony-message-bird-notifier
  • php-symfony-message-media-notifier
  • php-symfony-messenger
  • php-symfony-microsoft-graph-mailer
  • php-symfony-microsoft-teams-notifier
  • php-symfony-mime
  • php-symfony-mobyt-notifier
  • php-symfony-monolog-bridge
  • php-symfony-notifier
  • php-symfony-novu-notifier
  • php-symfony-ntfy-notifier
  • php-symfony-object-mapper
  • php-symfony-octopush-notifier
  • php-symfony-one-signal-notifier
  • php-symfony-options-resolver
  • php-symfony-orange-sms-notifier
  • php-symfony-ovh-cloud-notifier
  • php-symfony-pager-duty-notifier
  • php-symfony-password-hasher
  • php-symfony-phpunit-bridge
  • php-symfony-phrase-translation-provider
  • php-symfony-plivo-notifier
  • php-symfony-postal-mailer
  • php-symfony-postmark-mailer
  • php-symfony-primotexto-notifier
  • php-symfony-process
  • php-symfony-property-access
  • php-symfony-property-info
  • php-symfony-psr-http-message-bridge
  • php-symfony-pushover-notifier
  • php-symfony-pushy-notifier
  • php-symfony-rate-limiter
  • php-symfony-redis-messenger
  • php-symfony-redlink-notifier
  • php-symfony-remote-event
  • php-symfony-resend-mailer
  • php-symfony-ring-central-notifier
  • php-symfony-rocket-chat-notifier
  • php-symfony-routing
  • php-symfony-runtime
  • php-symfony-scaleway-mailer
  • php-symfony-scheduler
  • php-symfony-security-bundle
  • php-symfony-security-core
  • php-symfony-security-csrf
  • php-symfony-security-http
  • php-symfony-semaphore
  • php-symfony-sendberry-notifier
  • php-symfony-sendgrid-mailer
  • php-symfony-serializer
  • php-symfony-sevenio-notifier
  • php-symfony-simple-textin-notifier
  • php-symfony-sinch-notifier
  • php-symfony-sipgate-notifier
  • php-symfony-slack-notifier
  • php-symfony-sms-biuras-notifier
  • php-symfony-sms-factor-notifier
  • php-symfony-sms-sluzba-notifier
  • php-symfony-sms77-notifier
  • php-symfony-smsapi-notifier
  • php-symfony-smsbox-notifier
  • php-symfony-smsc-notifier
  • php-symfony-smsense-notifier
  • php-symfony-smsmode-notifier
  • php-symfony-spot-hit-notifier
  • php-symfony-stopwatch
  • php-symfony-string
  • php-symfony-sweego-mailer
  • php-symfony-sweego-notifier
  • php-symfony-telegram-notifier
  • php-symfony-telnyx-notifier
  • php-symfony-termii-notifier
  • php-symfony-translation
  • php-symfony-turbo-sms-notifier
  • php-symfony-twig-bridge
  • php-symfony-twig-bundle
  • php-symfony-twilio-notifier
  • php-symfony-twitter-notifier
  • php-symfony-type-info
  • php-symfony-uid
  • php-symfony-unifonic-notifier
  • php-symfony-validator
  • php-symfony-var-dumper
  • php-symfony-var-exporter
  • php-symfony-vonage-notifier
  • php-symfony-web-link
  • php-symfony-web-profiler-bundle
  • php-symfony-webhook
  • php-symfony-workflow
  • php-symfony-yaml
  • php-symfony-yunpian-notifier
  • php-symfony-zendesk-notifier
  • php-symfony-zulip-notifier
action needed
18 security issues in bullseye high

There are 18 open security issues in bullseye.

17 important issues:
  • CVE-2026-45063: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-45065: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle alternatives match as unanchored substrings, allowing a value such as //evil.com to satisfy a common locale requirement and generate a protocol-relative off-site URL. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-45067: ### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers treat it as a security boundary. The constructor accepts email addresses whose local-part (the part before `@`) is an RFC-5322 *quoted string* containing raw `\r\n` bytes — e.g. `"x\r\nBcc: attacker@evil"@example.com`. The stored address is later emitted verbatim into (1) the rendered message headers and (2) `SmtpTransport`'s `MAIL FROM:<...>` / `RCPT TO:<...>` protocol lines, turning the embedded CRLF into a new mail header and/or a new SMTP command. ### Resolution The `Address` constructor now rejects addresses containing line breaks. The patch for this issue is available [here](https://github.com/symfony/symfony/commit/dc2dbd29211eb4ddc451373fa1374fb926e94604) for branch 5.4. ### Credits We would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.
  • CVE-2026-45068: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a -- end-of-options separator, allowing an address beginning with - to be interpreted as a sendmail command-line option instead of an address. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-45069: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-45070: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-45071: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing attacker-supplied XML to expand file:// entities such as local files. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-45073: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence $prefix to break out of the LIKE literal and alter query semantics or deletion scope. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-45077: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with unserialize(base64_decode($message)) without authentication, integrity checks, or an allowed_classes allowlist, allowing any reachable host to submit attacker-chosen serialized PHP payloads that can crash the listener and may trigger object-injection gadget effects. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-45133: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parsers to recurse without a depth limit. A crafted document exhausts the PHP stack and crashes the worker. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-45304: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small untrusted YAML input to expand into a multi-gigabyte structure and exhaust memory. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-45305: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbitrarily long time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-46626:
  • CVE-2026-47767: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flags that change APP_ENV or APP_DEBUG. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
  • CVE-2026-48489: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler honored the request-supplied _failure_path parameter when failure_forward: true was enabled, allowing an unauthenticated failing login request to dispatch a subrequest to access_control-protected GET routes that skipped firewall listeners. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
  • CVE-2026-48736: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
  • CVE-2026-48784: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
1 issue postponed or untriaged:
  • CVE-2025-64500: (postponed; to be fixed through a stable update) Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.
Created: 2026-05-21 Last update: 2026-07-16 18:00
1 open merge request in Salsa normal
There is 1 open merge request for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2026-07-19 Last update: 2026-07-19 19:31
lintian reports 4 warnings normal
Lintian reports 4 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-06-30 Last update: 2026-06-30 04:47
debian/patches: 24 patches to forward upstream low

Among the 38 debian patches available in version 7.4.14+dfsg-1 of the package, we noticed the following issues:

  • 24 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-06-29 23:32
Issues found with some translations low

Automatic checks made by the Debian l10n team found some issues with the translations contained in this package. You should check the l10n status report for more information.

Issues can be things such as missing translations, problematic translated strings, outdated PO files, unknown languages, etc.

Created: 2020-02-26 Last update: 2020-02-26 10:49
news
[rss feed]
  • [2026-07-05] symfony 7.4.14+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-29] Accepted symfony 8.1.1+dfsg-1 (source) into experimental (David Prévot)
  • [2026-06-29] Accepted symfony 7.4.14+dfsg-1 (source) into unstable (David Prévot)
  • [2026-06-29] Accepted symfony 8.1.0+dfsg-1 (source all) into experimental (Debian FTP Masters) (signed by: David Prévot)
  • [2026-06-14] symfony 7.4.13+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-06-11] Accepted symfony 7.4.13+dfsg-2 (source) into unstable (David Prévot)
  • [2026-06-02] Accepted symfony 5.4.53+dfsg-0+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: David Prévot)
  • [2026-06-02] Accepted symfony 5.4.52+dfsg-0+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: David Prévot)
  • [2026-06-01] Accepted symfony 5.4.52+dfsg-0+deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: David Prévot)
  • [2026-06-01] Accepted symfony 5.4.53+dfsg-0+deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: David Prévot)
  • [2026-05-31] Accepted symfony 6.4.41+dfsg-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: David Prévot)
  • [2026-05-31] Accepted symfony 6.4.40+dfsg-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: David Prévot)
  • [2026-05-31] Accepted symfony 6.4.40+dfsg-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: David Prévot)
  • [2026-05-31] Accepted symfony 6.4.41+dfsg-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: David Prévot)
  • [2026-05-30] symfony 7.4.13+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-28] symfony 7.4.12+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-27] Accepted symfony 8.0.13+dfsg-1 (source) into experimental (David Prévot)
  • [2026-05-27] Accepted symfony 7.4.13+dfsg-1 (source) into unstable (David Prévot)
  • [2026-05-20] Accepted symfony 7.4.12+dfsg-1 (source) into unstable (David Prévot)
  • [2026-05-20] Accepted symfony 8.0.12+dfsg-1 (source) into experimental (David Prévot)
  • [2026-05-17] Accepted symfony 8.0.11+dfsg-1 (source) into experimental (David Prévot)
  • [2026-05-11] symfony REMOVED from testing (Debian testing watch)
  • [2026-05-09] Accepted symfony 8.0.10-1 (source) into experimental (David Prévot)
  • [2026-05-09] Accepted symfony 7.4.10+dfsg-1 (source) into unstable (David Prévot)
  • [2026-05-02] Accepted symfony 8.0.9+dfsg-1 (source) into experimental (David Prévot)
  • [2026-05-02] Accepted symfony 7.4.9+dfsg-1 (source) into unstable (David Prévot)
  • [2026-04-03] Accepted symfony 8.0.8+dfsg-1 (source) into experimental (David Prévot)
  • [2026-04-03] Accepted symfony 7.4.8+dfsg-1 (source) into unstable (David Prévot)
  • [2026-03-11] symfony 7.4.7+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-08] Accepted symfony 8.0.7+dfsg-1 (source) into experimental (David Prévot)
  • 1
  • 2
bugs [bug history graph]
  • all: 4
  • RC: 0
  • I&N: 1
  • M&W: 3
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 4)
  • buildd: logs, exp, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 100)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 7.4.14+dfsg-1ubuntu2
  • patches for 7.4.14+dfsg-1ubuntu2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing