Junglewise Threat Intelligence

CVE-2026-45073: Symfony SQL injection in PdoAdapter cache component

CVE-2026-45073 · Severity: medium · CVSS 4 · Published 2026-07-14

Technologies: Symfony. Vendors: Symfony.

Executive brief

Symfony is a popular PHP framework used to build web applications. A security flaw in its database-backed caching component could allow an attacker to manipulate database queries. This could lead to the unauthorized deletion of data or unexpected changes to how the application manages its stored information.

Technical details

An SQL injection vulnerability exists in the Symfony Cache component's PdoAdapter. The `doClear()` method constructs a SQL DELETE statement by concatenating a user-supplied `$prefix` variable directly into a LIKE clause without proper escaping or parameter binding. If an attacker can influence the prefix value, they can break out of the intended query structure to modify the deletion scope or execute arbitrary SQL logic. This issue affects Symfony versions prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12. The fix involves validating and properly handling the prefix input in the AbstractAdapter and PdoAdapter.

Affected products

  • Symfony Symfony < 5.4.52, >= 6.0.0-BETA1, < 6.4.40, >= 7.0.0-BETA1, < 7.4.12, >= 8.0.0-BETA1, < 8.0.12

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References