Vulnerability Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-request for each entry; because the array size is never bounded, an authenticated client can submit a single _batch request containing thousands of actions and exhaust CPU, memory, and database connections on the application server. This issue is fixed in versions 2.36.0 and 3.1.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symfony | Ux | >= 2.5.0, < 2.36.0 |
Related Weaknesses (CWE)
References
- https://github.com/symfony/ux/commit/95e878d5257f13d6d652ca95e3ef6bb0934d674fPatch
- https://github.com/symfony/ux/releases/tag/v2.36.0Release Notes
- https://github.com/symfony/ux/releases/tag/v3.1.0Release Notes
- https://github.com/symfony/ux/security/advisories/GHSA-mm82-c99c-h2cfVendor Advisory
FAQ
What is CVE-2026-49209?
CVE-2026-49209 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions arr...
How severe is CVE-2026-49209?
CVE-2026-49209 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-49209?
Check the references section above for vendor advisories and patch information. Affected products include: Symfony Ux.