CVE-2026-45755

MEDIUM

Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection

Title source: cna
STIX 2.1

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configured webhook secret but ignored the X-Mt-Signature HMAC header, allowing unauthenticated POST requests to inject forged Mailtrap delivery, bounce, open, click, or spam events. This issue is fixed in versions 7.4.12 and 8.0.12.

Scores

CVSS v3 5.3
EPSS 0.0024
EPSS Percentile 15.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306 CWE-347
Status published
Products (5)
/mailtrap-mailer/mailtrap-mailer >= 7.2.0, < 7.4.12
/mailtrap-mailer/mailtrap-mailer >= 8.0.0-BETA1, < 8.0.12
sensiolabs/symfony 7.2.0 - 7.4.12
symfony/symfony >= 7.2.0, < 7.4.12
symfony/symfony >= 8.0.0-BETA1, < 8.0.12
Published Jul 14, 2026
Tracked Since Jul 15, 2026