Executive brief
A vulnerability in the Symfony web framework allows unauthorized users to impersonate other people. By using a specially crafted digital certificate, an attacker can trick the system into identifying them as a different user, potentially gaining full access to that user's account and data. This affects applications using X.509 certificate-based authentication.
Technical details
The X509Authenticator in Symfony extracts user identifiers from the 'SSL_CLIENT_S_DN' server variable using an unanchored regular expression. This regex matches 'emailAddress=' anywhere within the Distinguished Name (DN) string rather than strictly at the start of a Relative Distinguished Name (RDN) boundary. An attacker with a valid, trusted certificate can embed a victim's email address within a different field (such as the Common Name) to successfully authenticate as that victim. The issue is resolved by anchoring the regex to RDN boundaries in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Affected products
- Symfony symfony/symfony < 5.4.52, >= 6.0.0-BETA1, < 6.4.40, >= 7.0.0-BETA1, < 7.4.12, >= 8.0.0-BETA1, < 8.0.12
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory
- 2026-05-20: patched: Release date of fixed versions
References
- https://github.com/symfony/symfony/commit/59ef484029601a7af06f5e06c6ed921fdcea5a0d
- https://github.com/symfony/symfony/releases/tag/v5.4.52
- https://github.com/symfony/symfony/releases/tag/v6.4.40
- https://github.com/symfony/symfony/releases/tag/v7.4.12
- https://github.com/symfony/symfony/releases/tag/v8.0.12
- https://github.com/symfony/symfony/security/advisories/GHSA-ph86-p8f6-f9r2