CVE-2026-45754
Summary
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not verify them, allowing unauthenticated POST requests to inject forged Mailjet and LOX24 event payloads. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
Impact & exploitability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: https://github.com/symfony/symfony/commit/3e52bf5ab733ee32e35eeeeb2631d859c941838e ↗
Additional information
- NVD record
- https://github.com/symfony/symfony/commit/3e52bf5ab733ee32e35eeeeb2631d859c941838ePatch
- https://github.com/symfony/symfony/commit/4aaa45dd054f73445f1ab254968b7e60b546cc77Patch
- https://github.com/symfony/symfony/security/advisories/GHSA-64hg-93w9-fc35Patch
- https://github.com/symfony/symfony/releases/tag/v6.4.40
- https://github.com/symfony/symfony/releases/tag/v7.4.12
- https://github.com/symfony/symfony/releases/tag/v8.0.12