Junglewise Threat Intelligence

CVE-2026-45077: Symfony MonologBridge PHP deserialization in server:log listener

CVE-2026-45077 · Severity: high · CVSS 4 · Published 2026-07-14

Technologies: Symfony. Vendors: Symfony.

Executive brief

Symfony is a popular PHP framework used to build web applications. A vulnerability in its logging component could allow an attacker to crash the logging service or potentially execute unauthorized code by sending specially crafted data to a network port that is open by default. This could lead to service disruptions or a compromise of the server's security.

Technical details

A deserialization of untrusted data vulnerability exists in the Symfony MonologBridge component. The 'server:log' listener (ServerLogCommand) binds to 0.0.0.0:9911 by default and processes incoming messages using 'unserialize(base64_decode($message))' without authentication, integrity checks, or class allowlisting. A remote attacker can send malicious PHP serialized payloads to this port to crash the listener or trigger object-injection gadget chains, potentially leading to remote code execution. The fix changes the default binding to localhost and implements safer handling. Patches are available in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

Affected products

  • symfony symfony < 5.4.52, >= 6.0.0-BETA1 < 6.4.40, >= 7.0.0-BETA1 < 7.4.12, >= 8.0.0-BETA1 < 8.0.12
  • symfony monolog-bridge < 5.4.52, >= 6.0.0-BETA1 < 6.4.40, >= 7.0.0-BETA1 < 7.4.12, >= 8.0.0-BETA1 < 8.0.12

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-05-20: patched

References