symfony/mailjet-mailer
Symfony Mailjet Mailer Bridge
Activity
- Latest release
- 3mo ago
- Total releases
- 76
- Cadence
- ~daily
- Last 12 months
- 13
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Sep 15, 2020
| Version | Released | |
|---|---|---|
v8.1.0
minor
|
v8.1.0
minor
Dependencies (1)
Changelog
Compare changes
|
|
v8.1.0-BETA3
pre
| ||
v8.0.12
patch
| ||
v7.4.12
patch
| ||
v6.4.40
patch
|
v6.4.40
patch
Dependencies (1)
Changelog
Compare changes
|
|
v8.1.0-BETA1
pre
| ||
v8.0.7
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.7
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.35
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.6
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.6
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.34
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.0
major
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.0
minor
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.5
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.27
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.24
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.0
minor
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev |
v7.3.0
minor
Changelog
Compare changes
|
|
v7.2.0
minor
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.1.6
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.13
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev |
v6.4.13
patch
Changelog
Compare changes
|
|
v5.4.45
patch
| ||
v7.1.1
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.0.8
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.8
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.4.40
patch
| ||
v7.1.0
minor
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.0.7
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.7
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.4.39
patch
| ||
v7.0.3
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.3
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.3.12
patch
| ||
v5.4.35
patch
| ||
v7.0.2
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.2
patch
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.0.0
major
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.0
minor
1 CVE
CVE-2026-45754
GHSA-64hg-93w9-fc35
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Medium
Network
Low
None
None
DescriptionThe Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application's webhook endpoint. Their As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc. Resolution
When no secret is configured the behaviour is unchanged: webhook authentication remains opt-in, but it is now actually enforced once opted in. The Mailjet patch is available here for branch 6.4. The LOX24 patch is available here for branch 7.4 (the LOX24 bridge was introduced in 7.1 and is not present in 6.4). CreditsSymfony would like to thank Himanshu Anand for reporting the issue, and Alexandre Daubois and Nicolas Grekas for providing the fixes. Affected versions
v6.4.0
v6.4.13
v6.4.2
v6.4.24
v6.4.27
v6.4.3
v6.4.34
v6.4.35
v6.4.7
v6.4.8
v7.0.0
v7.0.2
+ 23 more Show less
v7.0.3
v7.0.7
v7.0.8
v7.1.0
v7.1.0-BETA1
v7.1.0-RC1
v7.1.1
v7.1.6
v7.2.0
v7.2.0-BETA1
v7.2.0-RC1
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.5
v7.4.0
v7.4.0-BETA1
v7.4.0-RC1
v7.4.6
v7.4.7
v8.0.0
v8.0.6
v8.0.7
Fixed in
6.4.40
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.0.0-BETA3
pre
| ||
v6.4.0-BETA3
pre
| ||
v6.4.0-BETA1
pre
| ||
v7.0.0-BETA1
pre
| ||
v6.3.0
minor
| ||
v6.2.10
patch
| ||
v5.4.23
patch
| ||
v5.4.21
patch
| ||
v6.2.7
patch
| ||
v6.2.5
patch
| ||
v6.1.11
patch
| ||
v6.0.19
patch
|