Executive brief
The Auth0 SDK for Symfony, which helps developers integrate authentication into their web applications, was found to incorrectly accept security tokens via URL web addresses. This is a security risk because tokens in URLs are often recorded in server logs, browser history, and shared links, which could allow an unauthorized person to steal a session and access protected data. Organizations using this library should update to the latest version to ensure tokens are only accepted through secure, standard headers.
Technical details
A vulnerability exists in the Auth0 Symfony SDK's Authorizer security authenticator where OAuth 2.0 bearer access tokens are accepted via the 'token' URL query parameter in addition to the standard Authorization header. This behavior violates RFC 6750 Section 2.3 and leads to sensitive information exposure (CWE-200, CWE-598). An attacker who gains access to server logs, browser history, or Referer headers could retrieve these tokens to replay requests against protected API endpoints. The fix, introduced in version 5.9.0, restricts token acceptance to the Authorization header only.
Affected products
- Auth0 Auth0 Symfony SDK >= 5.0.0-BETA0, <= 5.8.0
Timeline
- 2026-06-10: patched: Version 5.9.0 released
- 2026-07-14: advisory: GitHub Advisory published
References
- https://github.com/auth0/symfony/security/advisories/GHSA-ffq7-hh2j-r24p
- https://github.com/auth0/symfony/commit/172d1d3e0b9d1e93610d786118389a811179bc8a
- https://github.com/auth0/symfony/commit/bd1851b14ae15e99cbe87c96496cf25da025288a
- https://github.com/auth0/symfony/releases/tag/5.9.0
- https://api.github.com/repos/auth0/symfony/security-advisories/GHSA-ffq7-hh2j-r24p