Known CVE
Symfony HttpFoundation - Access Control Bypass via PATH_INFO
Symfony HttpFoundation component >= 2.0.0 and prior to versions 5.4.50, 6.4.29, and 7.3.7 contains an access control bypass vulnerability. The Request class improperly interprets some PATH_INFO values, producing URL paths without a leading `/`. This allows bypassing access control rules that are built with the `/-prefix` assumption.
CVE-2025-64500
High2025CVSS 7.3CWE-647
cve2025 · symfony · auth-bypass
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website