CVE-2026-45133
HIGHSymfony: [Yaml] Harden the parser when handling untrusted input
Title source: cnaDescription
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parsers to recurse without a depth limit. A crafted document exhausts the PHP stack and crashes the worker. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
References (5)
Core 5
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/symfony/symfony/releases/tag/v8.0.12
X_Refsource_Misc x_refsource_misc
https://github.com/symfony/symfony/releases/tag/v7.4.12
X_Refsource_Confirm x_refsource_confirm
https://github.com/symfony/symfony/security/advisories/GHSA-c2p3-7m5p-cv8x
X_Refsource_Misc x_refsource_misc
https://github.com/symfony/symfony/releases/tag/v5.4.52
X_Refsource_Misc x_refsource_misc
https://github.com/symfony/symfony/releases/tag/v6.4.40
Scores
CVSS v3
7.5
EPSS
0.0074
EPSS Percentile
51.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1333
CWE-674
CWE-776
Status
published
Products (5)
sensiolabs/symfony
< 5.4.52
symfony/symfony
< 5.4.52
symfony/symfony
>= 6.0.0-BETA1, < 6.4.40
symfony/symfony
>= 7.0.0-BETA1, < 7.4.12
symfony/symfony
>= 8.0.0-BETA1, < 8.0.12
Published
Jul 14, 2026
Tracked Since
Jul 15, 2026