Junglewise Threat Intelligence

CVE-2026-50157: Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() an

CVE-2026-50157 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: auth0/symfony (Packagist). Vendors: Auth0, Packagist.

Executive brief

The Auth0 SDK for Symfony, which helps developers integrate authentication into their web applications, was found to incorrectly accept security tokens via URL web addresses. This is a security risk because tokens in URLs are often recorded in server logs, browser history, and shared links, which could allow an unauthorized person to steal a session and access protected data. Organizations using this library should update to the latest version to ensure tokens are only accepted through secure, standard headers.

Technical details

A vulnerability exists in the Auth0 Symfony SDK's Authorizer security authenticator where OAuth 2.0 bearer access tokens are accepted via the 'token' URL query parameter in addition to the standard Authorization header. This behavior violates RFC 6750 Section 2.3 and leads to sensitive information exposure (CWE-200, CWE-598). An attacker who gains access to server logs, browser history, or Referer headers could retrieve these tokens to replay requests against protected API endpoints. The fix, introduced in version 5.9.0, restricts token acceptance to the Authorization header only.

Affected products

  • Auth0 Auth0 Symfony SDK >= 5.0.0-BETA0, <= 5.8.0

Timeline

  • 2026-06-10: patched: Version 5.9.0 released
  • 2026-07-14: advisory: GitHub Advisory published

References

Related threats