CVE-2026-45069
Critical · CVSS 9.1symfony/security-http — JWT OIDC claim verification bypass (missing mandatory claims enforcement)
- CVSS
- 9.1
- nvd
- EPSS
- 0.24%
- 15th pct
- KEV
- No
- Class
- oss containerizable
- CWE-345, CWE-1287
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
Search profile — drives PoC discovery
Symbols OidcTokenHandlerverifyClaimsClaimCheckerManagercheckaudissexpOidcTokenHandler::verifyClaims
Keywords CVE-2026-45069symfony OIDC JWT claim bypassOidcTokenHandler verifyClaimsClaimCheckerManager mandatory claimssymfony security-http JWT bypassGHSA-29fc-p6c4-24cgsymfony OIDC aud iss exp missing claimssymfony JWT verification bypass
Versions: < 6.4.40, < 7.4.12, < 8.0.12
Affected packages
| Packagist | symfony/security-http | 6.3.0 → 6.4.40 |
| Packagist | symfony/security-http | 7.4.0 → 7.4.12 |
| Packagist | symfony/security-http | 8.0.0 → 8.0.12 |
| Packagist | symfony/symfony | 6.3.0 → 6.4.40 |
| Packagist | symfony/symfony | 7.4.0 → 7.4.12 |
| Packagist | symfony/symfony | 8.0.0 → 8.0.12 |
References
Status: enriched · ingested 2026-07-15T18:00:20.000Z · profiled 2026-07-15T18:30:20.000Z