CVE-2026-45063

CRITICAL

Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator

Title source: cna
STIX 2.1

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

Scores

CVSS v3 9.1
EPSS 0.0033
EPSS Percentile 25.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-290
Status published
Products (5)
sensiolabs/symfony < 5.4.52
symfony/symfony < 5.4.52
symfony/symfony >= 6.0.0-BETA1, < 6.4.40
symfony/symfony >= 7.0.0-BETA1, < 7.4.12
symfony/symfony >= 8.0.0-BETA1, < 8.0.12
Published Jul 14, 2026
Tracked Since Jul 15, 2026