Medium severity5.4NVD Advisory· Published May 16, 2019· Updated Jun 17, 2026
CVE-2019-10909
CVE-2019-10909
Description
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
symfony/symfonyPackagist | >= 2.7.0, < 2.7.51 | 2.7.51 |
symfony/symfonyPackagist | >= 2.8.0, < 2.8.50 | 2.8.50 |
symfony/symfonyPackagist | >= 3.0.0, < 3.4.26 | 3.4.26 |
symfony/symfonyPackagist | >= 4.0.0, < 4.1.12 | 4.1.12 |
symfony/symfonyPackagist | >= 4.2.0, < 4.2.7 | 4.2.7 |
symfony/framework-bundlePackagist | >= 2.7.0, < 2.7.51 | 2.7.51 |
symfony/framework-bundlePackagist | >= 2.8.0, < 2.8.50 | 2.8.50 |
symfony/framework-bundlePackagist | >= 3.0.0, < 3.4.26 | 3.4.26 |
symfony/framework-bundlePackagist | >= 4.0.0, < 4.1.12 | 4.1.12 |
symfony/framework-bundlePackagist | >= 4.2.0, < 4.2.7 | 4.2.7 |
drupal/corePackagist | >= 8.0.0, < 8.5.15 | 8.5.15 |
drupal/corePackagist | >= 8.6.0, < 8.6.15 | 8.6.15 |
drupal/drupalPackagist | >= 8.0.0, < 8.5.15 | 8.5.15 |
drupal/drupalPackagist | >= 8.6.0, < 8.6.15 | 8.6.15 |
Affected products
7- Symfony/Symfonydescription
- ghsa-coords4 versionspkg:composer/drupal/corepkg:composer/drupal/drupalpkg:composer/symfony/framework-bundlepkg:composer/symfony/symfony
>= 8.0.0, < 8.5.15+ 3 more
- (no CPE)range: >= 8.0.0, < 8.5.15
- (no CPE)range: >= 8.0.0, < 8.5.15
- (no CPE)range: >= 2.7.0, < 2.7.51
- (no CPE)range: >= 2.7.0, < 2.7.51
Patches
Vulnerability mechanics
References
11- github.com/symfony/symfony/commit/ab4d05358c3d0dd1a36fc8c306829f68e3dd84e2nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-g996-q5r8-w7g2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10909ghsaADVISORY
- symfony.com/blog/cve-2019-10909-escape-validation-messages-in-the-php-templating-enginenvdVendor AdvisoryWEB
- www.drupal.org/sa-core-2019-005nvdThird Party AdvisoryWEB
- www.synology.com/security/advisory/Synology_SA_19_19nvdThird Party AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2019-10909.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2019-10909.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/symfony/framework-bundle/CVE-2019-10909.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-10909.yamlghsaWEB
- symfony.com/cve-2019-10909ghsaWEB
News mentions
0No linked articles in our index yet.