CVE-2026-45754

medium

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not verify them, allowing unauthenticated POST requests to inject forged Mailjet and LOX24 event payloads. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

References

https://github.com/symfony/symfony/security/advisories/GHSA-64hg-93w9-fc35

https://github.com/symfony/symfony/releases/tag/v8.0.12

https://github.com/symfony/symfony/releases/tag/v7.4.12

https://github.com/symfony/symfony/releases/tag/v6.4.40

https://github.com/symfony/symfony/commit/4aaa45dd054f73445f1ab254968b7e60b546cc77

https://github.com/symfony/symfony/commit/3e52bf5ab733ee32e35eeeeb2631d859c941838e

Details

Source: Mitre, NVD

Published: 2026-07-14

Updated: 2026-07-21

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Severity: Medium

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00103