Junglewise Threat Intelligence

CVE-2026-48747: Symfony Mailomat Mailer signature algorithm downgrade in webhook parser

CVE-2026-48747 · Severity: medium · CVSS 0 · Published 2026-07-14

Vendors: Symfony.

Executive brief

Symfony is a popular PHP framework used to build web applications. A vulnerability in its Mailomat mailer component could allow an attacker to bypass security checks on incoming webhooks by forcing the system to use weaker, less secure encryption methods. This could potentially allow unauthorized requests to be processed as if they were legitimate communications from the Mailomat service.

Technical details

A signature algorithm downgrade vulnerability exists in the MailomatRequestParser::validateSignature() method within Symfony's Mailomat Mailer bridge. The parser incorrectly extracted the HMAC algorithm directly from the 'X-MOM-Webhook-Signature' request header and passed it to PHP's hash_hmac() function. This allowed a remote attacker to specify weak or broken cryptographic primitives (such as MD4 or MD5) instead of the documented SHA-256 requirement. An attacker could exploit this to forge webhook signatures if they can compute a valid HMAC for a weaker primitive. The issue is resolved in versions 7.4.13 and 8.0.13 by pinning the algorithm to SHA-256 and using constant-time comparison.

Affected products

  • Symfony symfony/mailomat-mailer >= 7.2.0, < 7.4.13; >= 8.0.0-BETA1, < 8.0.13
  • Symfony symfony/symfony >= 7.2.0, < 7.4.13; >= 8.0.0-BETA1, < 8.0.13

Timeline

  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-05-27: patched: Versions 7.4.13 and 8.0.13 released
  • 2026-07-14: disclosed: CVE-2026-48747 published to NVD

References