CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-45063

Critical · CVSS 9.1

symfony/security-http — Authentication Bypass via Spoofing (CWE-290) — unanchored regex in X.509 client certificate DN parsing

CVSS
9.1
nvd
EPSS
0.34%
26th pct
KEV
No
Class
oss containerizable
CWE-290

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

Search profile — drives PoC discovery

Symbols X509AuthenticatorSSL_CLIENT_S_DNemailAddress=extractUsernamegetRDNsauthenticate
Keywords CVE-2026-45063symfony X509Authenticator bypasssymfony SSL_CLIENT_S_DN regex bypasssymfony certificate authentication bypasssymfony emailAddress RDN spoofsymfony security-http X509symfony distinguished name unanchored regex
Versions: < 5.4.52, < 6.4.40, < 7.4.12, < 8.0.12

Affected packages

Packagist symfony/security-http 0 → 5.4.52
Packagist symfony/security-http 6.0.0-BETA1 → 6.4.40
Packagist symfony/security-http 7.0.0-BETA1 → 7.4.12
Packagist symfony/security-http 8.0.0-BETA1 → 8.0.12
Packagist symfony/symfony 0 → 5.4.52
Packagist symfony/symfony 6.0.0-BETA1 → 6.4.40
Packagist symfony/symfony 7.0.0-BETA1 → 7.4.12
Packagist symfony/symfony 8.0.0-BETA1 → 8.0.12

References

Status: enriched · ingested 2026-07-15T18:00:20.000Z · profiled 2026-07-15T18:30:20.000Z