CVE-2026-49858

MEDIUM

API Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate

Title source: cna
STIX 2.1

Description

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missing isCacheKeySafe gate in the JSON:API and HAL item normalizers causes a cross-user attribute leak. #[ApiProperty(security: ...)] is evaluated per request to decide whether a property is exposed. The componentsCache arrays in ApiPlatform\JsonApi\Serializer\ItemNormalizer and ApiPlatform\Hal\Serializer\ItemNormalizer are keyed on $context['cache_key'], which is set unconditionally before delegating to the parent normalizer. The component structure (attributes, relationships, links) computed for one request can therefore be reused for a subsequent request whose user has a different set of accessible properties. A user with lower privileges may end up seeing the structure of properties that the security predicate would otherwise have hidden for them. This issue has been fixed in versions 4.1.29, 4.2.26, and 4.3.12.

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0021
EPSS Percentile 11.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-524 CWE-639
Status published
Products (18)
api-platform/api-platform/hal >= 2.6.0, < 4.1.29
api-platform/api-platform/hal >= 4.2.0, < 4.2.25
api-platform/api-platform/hal >= 4.3.0, < 4.3.8
api-platform/api-platform/json-api >= 2.6.0, < 4.1.29
api-platform/api-platform/json-api >= 4.2.0, < 4.2.25
api-platform/api-platform/json-api >= 4.3.0, < 4.3.8
api-platform/core 2.6.0 - 4.1.29Packagist
api-platform/core 4.2.0 - 4.2.25Packagist
api-platform/core 4.3.0 - 4.3.8Packagist
api-platform/core >= 2.6.0, < 4.1.29
... and 8 more
Published Jul 01, 2026
Tracked Since Jul 02, 2026