CVE-2018-11386: Debian Linux

Medium severity, CVSS 5.9. EPSS: 1.6% chance of exploitation in the next 30 days.

An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Sensiolabs Symfony: from 2.7.0, before 2.7.48 (fixed in 2.7.48); from 2.8.0, before 2.8.41 (fixed in 2.8.41); from 3.3.0, before 3.3.17 (fixed in 3.3.17); from 3.4.0, before 3.4.11 (fixed in 3.4.11); from 4.0.0, before 4.0.11 (fixed in 4.0.11)

Published 2018-06-13. Last modified 2026-06-17.