api-platform/json-api
[READ ONLY] API Platform JSON:API component
Activity
- Latest release
- 8h ago
- Total releases
- 76
- Cadence
- ~3 days
- Last 12 months
- 42
Reach
- Stars
- 4
Details
- License
- MIT
- First release
- Jun 25, 2024
| Version | Released | |
|---|---|---|
v5.0.0-beta.2
pre
|
v5.0.0-beta.2
pre
Dependencies (8)
Changelog
Compare changes
|
|
v5.0.0-beta.1
pre
|
v5.0.0-beta.1
pre
Dependencies (8)
Changelog
Compare changes
|
|
v4.4.0-beta.3
pre
|
v4.4.0-beta.3
pre
Dependencies (8)
Changelog
Compare changes
|
|
v4.4.0-beta.1
pre
|
v4.4.0-beta.1
pre
Dependencies (8)
Changelog
Compare changes
|
|
v4.4.0-beta.2
pre
|
v4.4.0-beta.2
pre
Dependencies (8)
Changelog
Compare changes
|
|
v5.0.0-alpha.3
pre
|
v5.0.0-alpha.3
pre
Dependencies (8)
Changelog
Compare changes
|
|
v4.4.0-alpha.4
pre
|
v4.4.0-alpha.4
pre
Dependencies (8)
Changelog
Compare changes
|
|
v5.0.0-alpha.2
pre
|
v5.0.0-alpha.2
pre
Dependencies (8)
Changelog
Compare changes
|
|
v4.4.0-alpha.3
pre
|
v4.4.0-alpha.3
pre
Dependencies (8)
Changelog
Compare changes
|
|
v5.0.0-alpha.1
pre
|
v5.0.0-alpha.1
pre
Dependencies (8)
Changelog
Compare changes
|
|
v4.4.0-alpha.2
pre
|
v4.4.0-alpha.2
pre
Dependencies (8)
Changelog
Compare changes
|
|
v4.4.0-alpha.1
pre
|
v4.4.0-alpha.1
pre
Dependencies (8)
Changelog
Compare changes
|
|
v4.3.19
patch
| ||
v4.3.18
patch
| ||
v4.3.17
patch
| ||
v4.3.13
patch
| ||
v4.2.26
patch
|
v4.2.26
patch
Dependencies (8)
Changelog
Compare changes
|
|
v4.1.30
patch
|
v4.1.30
patch
Dependencies (7)
Changelog
Compare changes
|
|
v4.3.11
patch
|
v4.3.11
patch
Dependencies (8)
Changelog
Compare changes
|
|
v4.3.9
patch
| ||
v4.3.8
patch
|
v4.3.8
patch
Dependencies (8)
Changelog
Compare changes
|
|
v4.2.25
patch
|
v4.2.25
patch
Dependencies (8)
Changelog
Compare changes
|
|
v4.1.29
patch
|
v4.1.29
patch
Dependencies (7)
Changelog
Compare changes
|
|
v4.3.7
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev |
v4.3.7
patch
Dependencies (8)
Changelog
Compare changes
|
|
v4.3.6
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.3.5
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.3.3
minor
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.24
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev |
v4.2.24
patch
Dependencies (8)
Changelog
Compare changes
|
|
v4.3.0-beta.2
pre
| ||
v4.3.0-beta.1
pre
|
v4.3.0-beta.1
pre
Dependencies (8)
Changelog
Compare changes
|
|
v4.2.20
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.3.0-alpha.2
pre
|
v4.3.0-alpha.2
pre
Dependencies (8)
Changelog
Compare changes
|
|
v4.2.18
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev |
v4.2.18
patch
Dependencies (8)
Changelog
Compare changes
|
|
v4.2.15
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.14
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.11
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.10
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.8
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.7
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.6
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev |
v4.2.6
patch
Dependencies (8)
Changelog
Compare changes
|
|
v4.1.28
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev |
v4.1.28
patch
Dependencies (7)
Changelog
Compare changes
|
|
v4.2.4
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.3
minor
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev |
v4.2.3
minor
Dependencies (8)
Changelog
Compare changes
|
|
v4.1.26
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev |
v4.1.26
patch
Dependencies (7)
Changelog
Compare changes
|
|
v4.2.0-alpha.3
pre
|
v4.2.0-alpha.3
pre
Dependencies (8)
Changelog
Compare changes
|
|
v4.1.23
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.2.0-alpha.1
pre
| ||
v4.1.20
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
4.1.14
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev | ||
v4.1.12
patch
1 CVE
CVE-2026-49858
GHSA-pjhx-3c3w-9v23
Jul 10, 2026
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Impact
This is the same vulnerability class as GHSA-428q-q3vv-3fq3 / CVE-2025-31485, which fixed only the GraphQL Exploitation conditionsExploitation requires all of the following to coincide:
Patches
All three branches receive patched releases of WorkaroundsOverride the JSON:API and HAL Credits
Affected versions
4.1.14
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
+ 76 more Show less
v4.0.19
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.0-alpha.1
v4.1.0-alpha.2
v4.1.0-beta.1
v4.1.0-beta.2
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.21
v4.1.22
v4.1.23
v4.1.24
v4.1.25
v4.1.26
v4.1.27
v4.1.28
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.10
v4.2.11
v4.2.12
v4.2.13
v4.2.14
v4.2.15
v4.2.16
v4.2.17
v4.2.18
v4.2.19
v4.2.2
v4.2.20
v4.2.21
v4.2.22
v4.2.23
v4.2.24
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
Fixed in
4.1.29
4.2.25
4.3.8
References Updated Jul 10, 2026 · Source: OSV.dev |