CVE-2026-45305

HIGH

Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex

Title source: cna
STIX 2.1

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbitrarily long time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

Scores

CVSS v3 7.5
EPSS 0.0080
EPSS Percentile 53.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1333
Status published
Products (9)
sensiolabs/symfony < 5.4.52
symfony/symfony < 5.4.52
symfony/symfony >= 6.0.0-BETA1, < 6.4.40
symfony/symfony >= 7.0.0-BETA1, < 7.4.12
symfony/symfony >= 8.0.0-BETA1, < 8.0.12
symfony/yaml < 5.4.52
symfony/yaml >= 6.0.0-BETA1, < 6.4.40
symfony/yaml >= 7.0.0-BETA1, < 7.4.12
symfony/yaml >= 8.0.0-BETA1, < 8.0.12
Published Jul 14, 2026
Tracked Since Jul 15, 2026