CVE-2026-45069
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-345, CWE-1287
- Published
- 2026-07-14
- Last modified
- 2026-07-14
Affected products
- symfony symfony
- symfony symfony
- symfony symfony
- symfony security-http
- symfony security-http
- symfony security-http
Weakness type
Related vulnerabilities
- CVE-2026-80172 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-73316 — XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider
- CVE-2026-85008 — undici vulnerable to caching and replay of unsafe HTTP method responses
- CVE-2026-85621 — LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu
- CVE-2026-85435 — MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment
- CVE-2026-85434 — MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping
- CVE-2026-85431 — MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injection
- CVE-2026-85430 — MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing