CVE-2024-50342: Sensiolabs Httpclient

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

  • Sensiolabs Httpclient: before 5.4.46 (fixed in 5.4.46); from 6.0.0, before 6.4.14 (fixed in 6.4.14); from 7.0.0, before 7.1.7 (fixed in 7.1.7)

Published 2024-11-06. Last modified 2026-06-17.