/Vulnerability Library

Symfony HttpFoundation - Access Control Bypass via PATH_INFO

CVE-2025-64500
Verified

Description

Symfony HttpFoundation component >= 2.0.0 and prior to versions 5.4.50, 6.4.29, and 7.3.7 contains an access control bypass vulnerability. The Request class improperly interprets some PATH_INFO values, producing URL paths without a leading `/`. This allows bypassing access control rules that are built with the `/-prefix` assumption.

Severity

High

CVSS Score

7.3

Exploit Probability

1%

Affected Product

symfony

Published Date

April 2, 2026

Template Author

dhiyaneshdk

CVE-2025-64500.yaml
7.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVE ID:
cve-2025-64500
CWE ID:
cwe-647

References

https://github.com/symfony/symfony/security/advisories/GHSA-3rg7-wf37-54rmhttps://symfony.com/blog/cve-2025-64500-incorrect-parsing-of-path-info-can-lead-to-limited-authorization-bypasshttps://github.com/symfony/symfony/commit/9962b91b12bb791322fa73836b350836b6db7cachttps://nvd.nist.gov/vuln/detail/CVE-2025-64500

Remediation Steps

Update to Symfony versions 5.4.50, 6.4.29, or 7.3.7 or later.