symfony/ux-live-component
Live components for Symfony
Activity
- Latest release
- 6d ago
- Total releases
- 63
- Cadence
- ~13 days
- Last 12 months
- 11
Reach
- Stars
- 165
Details
- License
- MIT
- First release
- Dec 09, 2021
| Version | Released | |
|---|---|---|
v3.4.0
minor
|
v3.4.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
v3.3.0
minor
| ||
v3.2.0
minor
| ||
v3.1.0
minor
| ||
v2.36.0
minor
|
v2.36.0
minor
Dependencies (6)
Changelog
Compare changes
|
|
v3.0.0
major
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.35.0
minor
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.34.0
minor
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev |
v2.34.0
minor
Dependencies (6)
Changelog
Compare changes
|
|
v2.33.0
minor
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.32.0
minor
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev |
v2.32.0
minor
Dependencies (6)
Changelog
Compare changes
|
|
v2.31.0
minor
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.30.0
minor
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.29.2
patch
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.29.1
patch
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.29.0
minor
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.28.2
patch
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev |
v2.28.2
patch
Dependencies (6)
Changelog
Compare changes
|
|
v2.28.1
patch
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev |
v2.28.1
patch
Changelog
Compare changes
|
|
v2.28.0
minor
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.27.0
minor
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.26.1
patch
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.26.0
minor
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.25.2
patch
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.25.1
patch
5 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev | ||
v2.25.0
minor
6 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.24.0
minor
6 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.23.0
minor
6 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.22.1
patch
6 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.22.0
minor
6 CVEs
CVE-2026-49215
GHSA-4m4j-hmqq-3gxm
Jun 19, 2026
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
Low
Network
Low
None
DescriptionWhen using The In practice the attack is mitigated by Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
+ 11 more Show less
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.21.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.20.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.19.2
patch
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.19.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.18.1
patch
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.18.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.17.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.16.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.15.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.14.2
patch
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.14.1
patch
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.14.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.13.3
patch
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.13.2
patch
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.13.1
patch
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.13.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.12.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.11.2
patch
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.11.1
patch
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.11.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.10.0
minor
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev | ||
v2.9.1
patch
5 CVEs
CVE-2026-49212
GHSA-34w5-c283-j9fg
Jun 19, 2026
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
Low
Network
High
Low
None
DescriptionIn The HMAC computed by ResolutionThe HMAC is now bound to its context: the component name and a slot identifier are included in the pre-image before hashing. Two constants ( The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Anthropic (via Project Glasswing) for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49210
GHSA-38x5-rcv4-xf7x
Jun 19, 2026
symfony/ux-live-component: XSS via attacker-controlled child component tag
Medium
Network
Low
None
Description
In the default configuration, the Live Component endpoint is gated by an Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49209
GHSA-mm82-c99c-h2cf
Jun 19, 2026
symfony/ux-live-component: Denial of service via unbounded batch action requests
Low
Network
Low
Low
None
Description
Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 41 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-49208
GHSA-89g7-22c8-3j23
Jun 19, 2026
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
Medium
Network
Low
None
None
DescriptionWhen a Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
+ 36 more Show less
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-47946
GHSA-5j3w-5pcr-f8hg
May 19, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactRendering PatchesThe issue is fixed in version WorkaroundsUntil you can upgrade, avoid rendering ReferencesGitHub repository: symfony/ux Affected versions
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
+ 30 more Show less
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.25.1
References
Updated Aug 29, 2025 · Source: OSV.dev |