← Back

CVE-2025-64500

Published: Nov 12, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: security-advisories@github.com (Secondary)

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.

Affected (6)

2 products
Httpfoundation
Symfony
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Sensiolabs
From 2.0.0 to 5.4.50
From 6.0.0 to 6.4.29
From 7.0.0 to 7.3.7
Sensiolabs
From 2.0.0 to 5.4.50
From 6.0.0 to 6.4.29
From 7.0.0 to 7.3.7

Timeline

No history available yet.