Medium severity5.3OSV Advisory· Published Jul 14, 2026· Updated Jul 15, 2026
CVE-2026-45755
CVE-2026-45755
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configured webhook secret but ignored the X-Mt-Signature HMAC header, allowing unauthenticated POST requests to inject forged Mailtrap delivery, bounce, open, click, or spam events. This issue is fixed in versions 7.4.12 and 8.0.12.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
symfony/mailtrap-mailerPackagist | >= 7.2.0, < 7.4.12 | 7.4.12 |
symfony/mailtrap-mailerPackagist | >= 8.0.0, < 8.0.12 | 8.0.12 |
symfony/symfonyPackagist | >= 7.2.0, < 7.4.12 | 7.4.12 |
symfony/symfonyPackagist | >= 8.0.0, < 8.0.12 | 8.0.12 |
Affected products
1- Range: v8.0.11, v7.4.11, v8.0.10, …
Patches
Vulnerability mechanics
References
8- github.com/symfony/symfony/commit/4e0467e4e182cf2e704a3d9e1bc1a6be65d52ab8nvdPatchWEB
- github.com/symfony/symfony/security/advisories/GHSA-59f3-vp2f-mp9wnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-59f3-vp2f-mp9wghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/symfony/mailtrap-mailer/CVE-2026-45755.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2026-45755.yamlghsaWEB
- github.com/symfony/symfony/releases/tag/v7.4.12nvdProductRelease Notes
- github.com/symfony/symfony/releases/tag/v8.0.12nvdProductRelease Notes
- symfony.com/cve-2026-45755ghsaWEB
News mentions
0No linked articles in our index yet.