Executive brief
Symfony is a popular PHP framework used to build web applications. A vulnerability in its DomCrawler component could allow an attacker to read sensitive files from the server's local storage by submitting specially crafted XML data. This could lead to the exposure of configuration files, credentials, or other private system information.
Technical details
An XML External Entity (XXE) vulnerability exists in the Symfony DomCrawler component's Crawler::addXmlContent() method. The root cause is that the method explicitly sets DOMDocument::$validateOnParse to true before calling loadXML(), which re-enables external entity resolution even if it was otherwise disabled. A remote, unauthenticated attacker can exploit this by providing malicious XML content containing file:// entities, leading to arbitrary local file disclosure. The issue is resolved in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12 by removing the problematic property assignment.
Affected products
- Symfony symfony/symfony < 5.4.52, >= 6.0.0-BETA1 < 6.4.40, >= 7.0.0-BETA1 < 7.4.12, >= 8.0.0-BETA1 < 8.0.12
- Symfony symfony/dom-crawler < 5.4.52, >= 6.0.0-BETA1 < 6.4.40, >= 7.0.0-BETA1 < 7.4.12, >= 8.0.0-BETA1 < 8.0.12
Timeline
- 2026-05-20: patched: Security releases 5.4.52, 6.4.40, 7.4.12, and 8.0.12 published.
- 2026-07-14: disclosed: CVE-2026-45071 published.
References
- https://github.com/symfony/symfony/commit/eea5fd7488cbdc241da4ce242344b7d9a3ecdf3d
- https://github.com/symfony/symfony/releases/tag/v5.4.52
- https://github.com/symfony/symfony/releases/tag/v6.4.40
- https://github.com/symfony/symfony/releases/tag/v7.4.12
- https://github.com/symfony/symfony/releases/tag/v8.0.12
- https://github.com/symfony/symfony/security/advisories/GHSA-x6g4-fwcc-jj8w