symfony/http-foundation
Defines an object-oriented layer for the HTTP specification
Activity
- Latest release
- 2w ago
- Total releases
- 689
- Cadence
- ~daily
- Last 12 months
- 59
Reach
- Stars
- 8.6k
Details
- License
- MIT
- First release
- Sep 29, 2011
| Version | Released | |
|---|---|---|
v8.1.6
patch
|
v8.1.6
patch
Dependencies (2)
Changelog
Compare changes
|
|
v7.4.18
patch
| ||
v6.4.45
patch
|
v6.4.45
patch
Dependencies (3)
Changelog
Compare changes
|
|
v8.1.5
patch
|
v8.1.5
patch
Dependencies (2)
Changelog
Compare changes
|
|
v7.4.17
patch
| ||
v6.4.44
patch
|
v6.4.44
patch
Dependencies (3)
Changelog
Compare changes
|
|
v8.1.4
patch
|
v8.1.4
patch
Dependencies (2)
Changelog
Compare changes
|
|
v7.4.16
patch
| ||
v8.1.2
patch
|
v8.1.2
patch
Dependencies (2)
Changelog
Compare changes
|
|
v8.0.15
patch
| ||
v7.4.15
patch
| ||
v6.4.43
patch
|
v6.4.43
patch
Dependencies (3)
Changelog
Compare changes
|
|
v6.4.42
patch
| ||
v8.1.1
patch
| ||
v8.0.14
patch
| ||
v7.4.14
patch
| ||
v8.1.0
minor
| ||
v8.1.0-RC1
pre
| ||
v8.0.13
patch
| ||
v7.4.13
patch
| ||
v6.4.41
patch
| ||
v8.1.0-BETA3
pre
| ||
v8.1.0-BETA1
pre
| ||
v8.0.8
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.8
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.7
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.7
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.35
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.6
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.6
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.34
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.5
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.5
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.11
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.33
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.4
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.4
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.10
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.32
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.3
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.3
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.9
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.31
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.1
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.1
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.8
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.30
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.0
major
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.0
minor
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.7
patch
1 CVE
CVE-2026-48736
GHSA-38cx-cq6f-5755
Jun 15, 2026
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Medium
Network
Low
None
None
Description
Real-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4. ResolutionThe private-subnet list now includes The patches for this issue are available here for branch 5.4 and here for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1). CreditsSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix. Affected versions
v6.4.0
v6.4.10
v6.4.12
v6.4.13
v6.4.14
v6.4.15
v6.4.16
v6.4.18
v6.4.2
v6.4.21
v6.4.22
v6.4.23
+ 79 more Show less
v6.4.24
v6.4.25
v6.4.26
v6.4.28
v6.4.29
v6.4.3
v6.4.30
v6.4.31
v6.4.32
v6.4.33
v6.4.34
v6.4.35
v6.4.4
v6.4.7
v6.4.8
v7.0.0
v7.0.10
v7.0.3
v7.0.4
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.10
v7.1.11
v7.1.3
v7.1.5
v7.1.6
v7.1.7
v7.1.8
v7.1.9
v7.2.0
v7.2.0-BETA1
v7.2.0-BETA2
v7.2.0-RC1
v7.2.2
v7.2.3
v7.2.5
v7.2.6
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-BETA2
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.11
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-BETA2
v7.4.0-RC1
v7.4.1
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.5
v8.0.6
v8.0.7
v8.0.8
Fixed in
6.4.41
7.4.13
8.0.13
References
Updated Sep 10, 2026 · Source: OSV.dev |