Executive brief
A vulnerability in the Symfony PHP framework's YAML parsing component can allow an attacker to crash or slow down a web application. By providing a specially crafted YAML file, an attacker can trigger a process that consumes excessive server resources, leading to a denial-of-service. This affects any application that uses Symfony to process untrusted YAML data, such as configuration uploads or API inputs.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in Symfony\Component\Yaml\Parser::cleanup() due to the use of regular expressions with overlapping quantifiers. Specifically, the regexes used for YAML directives, comments, and document markers are susceptible to catastrophic backtracking when processing malicious input. An unauthenticated remote attacker can exploit this by submitting crafted YAML content to an endpoint that parses it, causing the PHP process to hang for an arbitrarily long time and exhausting server resources. The issue is resolved in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12 by hardening the regexes with possessive quantifiers and unambiguous character classes.
Affected products
- symfony symfony < 5.4.52, >= 6.0.0-BETA1, < 6.4.40, >= 7.0.0-BETA1, < 7.4.12, >= 8.0.0-BETA1, < 8.0.12
- symfony yaml < 5.4.52, >= 6.0.0-BETA1, < 6.4.40, >= 7.0.0-BETA1, < 7.4.12, >= 8.0.0-BETA1, < 8.0.12
Timeline
- 2026-07-14: advisory: NVD publication date
- 2026-07-14: disclosed: GitHub advisory published
References
- https://github.com/symfony/symfony/commit/9749cd43c5e09b3735093623670b21b9d8a056cb
- https://github.com/symfony/symfony/releases/tag/v5.4.52
- https://github.com/symfony/symfony/releases/tag/v6.4.40
- https://github.com/symfony/symfony/releases/tag/v7.4.12
- https://github.com/symfony/symfony/releases/tag/v8.0.12
- https://github.com/symfony/symfony/security/advisories/GHSA-9frc-8383-795m