symfony/json-path
Eases JSON navigation using the JSONPath syntax as described in RFC 9535
Activity
- Latest release
- 1mo ago
- Total releases
- 29
- Cadence
- ~7 days
- Last 12 months
- 22
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Apr 27, 2025
| Version | Released | |
|---|---|---|
v8.1.2
patch
|
v8.1.2
patch
Dependencies (2)
Changelog
Compare changes
|
|
v8.0.15
patch
| ||
v7.4.15
patch
| ||
v8.1.0
minor
| ||
v8.1.0-BETA3
pre
| ||
v8.0.12
patch
| ||
v7.4.12
patch
| ||
v8.1.0-BETA1
pre
| ||
v8.0.8
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.8
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.4
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.4
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.10
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.3
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.3
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.9
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.1
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.1
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.8
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.0
major
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.0
minor
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.0-BETA1
pre
| ||
v7.4.0-BETA1
pre
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.5
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.4
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.2
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.1
patch
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev |
v7.3.1
patch
Changelog
Compare changes
|
|
v7.3.0
initial
1 CVE
CVE-2026-45756
GHSA-8v8v-g73j-492j
May 28, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
Network
Low
None
None
DescriptionThe
Conditions for exploitationAn application that evaluates an attacker-influenced JSONPath expression containing a Resolution
The patch for this issue is available here for branch 7.4. CreditsSymfony would like to thank Himanshu Anand for reporting the issue and Alexandre Daubois for providing the fix. Affected versions
v7.3.0
v7.3.1
v7.3.10
v7.3.2
v7.3.4
v7.3.5
v7.3.8
v7.3.9
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.1
+ 8 more Show less
v7.4.3
v7.4.4
v7.4.8
v8.0.0
v8.0.1
v8.0.3
v8.0.4
v8.0.8
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.0-BETA2
pre
|