CVE-2019-18887: Fedoraproject Fedora
High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
Affected products
- Fedoraproject Fedora: version 30 only; version 31 only
- Sensiolabs Symfony: from 2.8.0, up to and including 2.8.50; from 3.4.0, up to and including 3.4.34; from 4.2.0, up to and including 4.2.11; from 4.3.0, up to and including 4.3.7
Published 2019-11-21. Last modified 2026-06-17.