CVE-2026-45075

NameCVE-2026-45075
DescriptionSymfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check is skipped, allowing protected controllers to execute and leak headers or perform side effects. This issue is fixed in versions 7.4.12 and 8.0.12.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
symfony (PTS)bullseye4.4.19+dfsg-2+deb11u6fixed
bullseye (security)4.4.19+dfsg-2+deb11u7fixed
bookworm, bookworm (security)5.4.53+dfsg-0+deb12u1fixed
trixie (security), trixie6.4.41+dfsg-0+deb13u1fixed
forky, sid7.4.14+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
symfonysourcebullseye(not affected)
symfonysourcebookworm(not affected)
symfonysourcetrixie(not affected)
symfonysource(unstable)7.4.12+dfsg-1

Notes

[trixie] - symfony <not-affected> (Vulnerable code not present, introduced in 7.4)
[bookworm] - symfony <not-affected> (Vulnerable code not present, introduced in 7.4)
[bullseye] - symfony <not-affected> (Vulnerable code not present, introduced in 7.4)
https://symfony.com/blog/cve-2026-45075-head-request-bypasses-methods-get-filter-in-isgranted-issignaturevalid-iscsrftokenvalid

Search for package or bug name: Reporting problems