Junglewise Threat Intelligence

CVE-2026-45065: Symfony open redirect in UrlGenerator route validation

CVE-2026-45065 · Severity: medium · CVSS 6.1 · Published 2026-07-14

Technologies: Symfony. Vendors: Symfony.

Executive brief

Symfony, a popular web application framework for PHP, contains a vulnerability in its URL generation component. An attacker could potentially trick the system into generating links that lead to malicious external websites instead of the intended internal pages. This could be used in phishing attacks to steal user credentials or redirect users to harmful content.

Technical details

A vulnerability exists in the Symfony Routing component's UrlGenerator. The component validates route parameters against a pattern constructed as '^' plus the raw requirement plus ' . When using ungrouped alternations in requirements (e.g., 'fr|en'), middle alternatives can match as unanchored substrings. This allows an attacker to provide a value such as '//evil.com' that satisfies a common requirement (like a locale) but results in the generation of a protocol-relative off-site URL. This is classified as an open redirect (CWE-601) caused by an incorrect regular expression (CWE-185). The issue is fixed in Symfony versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

Affected products

  • Symfony Symfony < 5.4.52, >= 6.0.0-BETA1 < 6.4.40, >= 7.0.0-BETA1 < 7.4.12, >= 8.0.0-BETA1 < 8.0.12

Timeline

  • 2026-05-20: patched: Fixes released in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12
  • 2026-07-14: advisory: CVE published by NVD

References

Related threats