Skip to content

Known CVE

Symfony HttpFoundation - Access Control Bypass via PATH_INFO

Symfony HttpFoundation component >= 2.0.0 and prior to versions 5.4.50, 6.4.29, and 7.3.7 contains an access control bypass vulnerability. The Request class improperly interprets some PATH_INFO values, producing URL paths without a leading `/`. This allows bypassing access control rules that are built with the `/-prefix` assumption.

CVE-2025-64500

High2025CVSS 7.3CWE-647

cve2025 · symfony · auth-bypass

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website