Executive brief
Symfony is a popular PHP framework used to build web applications. A security flaw in its database-backed caching component could allow an attacker to manipulate database queries. This could lead to the unauthorized deletion of data or unexpected changes to how the application manages its stored information.
Technical details
An SQL injection vulnerability exists in the Symfony Cache component's PdoAdapter. The `doClear()` method constructs a SQL DELETE statement by concatenating a user-supplied `$prefix` variable directly into a LIKE clause without proper escaping or parameter binding. If an attacker can influence the prefix value, they can break out of the intended query structure to modify the deletion scope or execute arbitrary SQL logic. This issue affects Symfony versions prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12. The fix involves validating and properly handling the prefix input in the AbstractAdapter and PdoAdapter.
Affected products
- Symfony Symfony < 5.4.52, >= 6.0.0-BETA1, < 6.4.40, >= 7.0.0-BETA1, < 7.4.12, >= 8.0.0-BETA1, < 8.0.12
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory
References
- https://github.com/symfony/symfony/commit/ec50b799d79ebe24561f29351c1efcb6da95c9b1
- https://github.com/symfony/symfony/releases/tag/v5.4.52
- https://github.com/symfony/symfony/releases/tag/v6.4.40
- https://github.com/symfony/symfony/releases/tag/v7.4.12
- https://github.com/symfony/symfony/releases/tag/v8.0.12
- https://github.com/symfony/symfony/security/advisories/GHSA-6qh9-h6wf-jgqc