CVE-2024-51996: Symfony

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8.

Affected products

  • Symfony Symfony: from 5.3.0, before 5.4.47 (fixed in 5.4.47); from 6.0.0-BETA1, before 6.4.15 (fixed in 6.4.15); from 7.0.0-BETA1, before 7.1.8 (fixed in 7.1.8)
  • Symphony PHP Framework Symphony Process: up to and including 5.3.0; before 5.4.47 (fixed in 5.4.47); up to and including 6.0.0-BETA1; before 6.4.15 (fixed in 6.4.15); up to and including 7.0.0-BETA1; before 7.1.8 (fixed in 7.1.8)

Published 2024-11-13. Last modified 2026-06-17.