VYPR
Critical severity9.1OSV Advisory· Published Jul 14, 2026· Updated Jul 15, 2026

CVE-2026-45063

CVE-2026-45063

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
symfony/security-httpPackagist
< 5.4.525.4.52
symfony/security-httpPackagist
>= 6.0.0-BETA1, < 6.4.406.4.40
symfony/security-httpPackagist
>= 7.0.0-BETA1, < 7.4.127.4.12
symfony/security-httpPackagist
>= 8.0.0-BETA1, < 8.0.128.0.12
symfony/symfonyPackagist
< 5.4.525.4.52
symfony/symfonyPackagist
>= 6.0.0-BETA1, < 6.4.406.4.40
symfony/symfonyPackagist
>= 7.0.0-BETA1, < 7.4.127.4.12
symfony/symfonyPackagist
>= 8.0.0-BETA1, < 8.0.128.0.12

Affected products

1

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.