CVE-2026-45063Sensiolabs · Symfony
Vulnerability data via NVD (ingested)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-45063product:"Sensiolabs Symfony"http.html:"Symfony"More intel sources (5)
vuln:CVE-2026-45063vulnerabilities.cve_id: CVE-2026-45063CVE-2026-45063CVE-2026-45063"CVE-2026-45063" exploit -site:nvd.nist.gov