CVE-2024-50343: Symfony
Low severity, CVSS 3.1. EPSS: 0.5% chance of exploitation in the next 30 days.
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. Symfony as of versions 5.4.43, 6.4.11, and 7.1.4 now uses the `D` regex modifier to match the entire input. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected products
- Symfony Symfony: before 5.4.43 (fixed in 5.4.43); from 6.0.0, before 6.4.11 (fixed in 6.4.11); from 7.0.0, before 7.1.4 (fixed in 7.1.4)
Published 2024-11-06. Last modified 2026-06-17.