CVE-2026-45071
LOW SEVERITYVulnerability Description
Symfony has XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
composer
Product
symfony/dom-crawler
External References
- https://github.com/symfony/symfony/security/advisories/GHSA-x6g4-fwcc-jj8w
- https://github.com/symfony/symfony/commit/eea5fd7488cbdc241da4ce242344b7d9a3ecdf3d
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/dom-crawler/CVE-2026-45071.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2026-45071.yaml
- https://symfony.com/cve-2026-45071
- https://github.com/advisories/GHSA-x6g4-fwcc-jj8w
Discussion (0)
Add Comment
No comments yet. Be the first!