Medium severityNVD Advisory· Published Jul 14, 2026
Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter
CVE-2026-50157
Description
Description
Applications built with the Auth0 Symphony SDK, using the Authorizer security authenticator to protect HTTP routes may accept OAuth 2.0 bearer access tokens provided through a URL query parameter, in addition to the standard Authorization header, which may increase the risk of access token exposure and replay against protected API endpoints.
Resolution
Upgrade auth0/symfony to version 5.9.0 or greater.
Acknowledgement
Okta would like to thank Alex Yeara for their discovery.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
auth0/symfonyPackagist | >= 5.0.0-BETA0, < 5.9.0 | 5.9.0 |
Affected products
1- Range: >=5.9.0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-ffq7-hh2j-r24pghsaADVISORY
- github.com/auth0/symfony/commit/172d1d3e0b9d1e93610d786118389a811179bc8aghsaWEB
- github.com/auth0/symfony/commit/bd1851b14ae15e99cbe87c96496cf25da025288aghsaWEB
- github.com/auth0/symfony/releases/tag/5.9.0ghsaWEB
- github.com/auth0/symfony/security/advisories/GHSA-ffq7-hh2j-r24pghsaWEB
News mentions
0No linked articles in our index yet.