api-platform/hal
API Platform HAL component
Activity
- Latest release
- 9h ago
- Total releases
- 34
- Cadence
- ~2 days
- Last 12 months
- 33
Reach
- Stars
- 3
Details
- License
- MIT
- First release
- Sep 16, 2025
| Version | Released | |
|---|---|---|
v5.0.0-beta.2
pre
| ||
v5.0.0-beta.1
pre
| ||
v4.4.0-beta.3
pre
| ||
v4.4.0-beta.1
pre
| ||
v4.4.0-beta.2
pre
| ||
v5.0.0-alpha.3
pre
| ||
v5.0.0-alpha.2
pre
| ||
v4.4.0-alpha.4
pre
| ||
v4.4.0-alpha.3
pre
| ||
v4.3.19
patch
| ||
v4.3.18
patch
| ||
v4.3.17
patch
| ||
v5.0.0-alpha.1
pre
| ||
v4.4.0-alpha.2
pre
| ||
v4.4.0-alpha.1
pre
| ||
v4.3.15
patch
| ||
v4.2.26
patch
| ||
v4.3.11
patch
| ||
v4.3.8
patch
| ||
v4.2.25
patch
| ||
v4.3.7
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.20
v4.2.21
+ 18 more Show less
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.3.4
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.20
v4.2.21
+ 18 more Show less
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.3.3
minor
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.20
v4.2.21
+ 18 more Show less
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.3.0-beta.2
pre
| ||
v4.3.0-beta.1
pre
| ||
v4.2.24
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.20
v4.2.21
+ 18 more Show less
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.3.0-alpha.2
pre
| ||
v4.2.17
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.20
v4.2.21
+ 18 more Show less
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.15
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.20
v4.2.21
+ 18 more Show less
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.14
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.20
v4.2.21
+ 18 more Show less
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.11
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.20
v4.2.21
+ 18 more Show less
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.7
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.20
v4.2.21
+ 18 more Show less
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.6
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.20
v4.2.21
+ 18 more Show less
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.3
initial
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.20
v4.2.21
+ 18 more Show less
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev |