Vulnerability Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\EntitySearchUtil::addSearchClause() builds the LIKE expression used by the autocomplete endpoint by wrapping the client-supplied query in %...% without escaping SQL LIKE wildcards (%, _, \), allowing unauthenticated users to turn the public BaseEntityAutocompleteType endpoint into a broad matcher or blind boolean oracle against every column in default searchable_fields. This issue is fixed in versions 2.36.0 and 3.1.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symfony | Ux | >= 2.2.0, < 2.36.0 |
Related Weaknesses (CWE)
References
- https://github.com/symfony/ux/commit/725ab3d40689c91ff19ad2d01940a30007769214Patch
- https://github.com/symfony/ux/releases/tag/v2.36.0Release Notes
- https://github.com/symfony/ux/releases/tag/v3.1.0Release Notes
- https://github.com/symfony/ux/security/advisories/GHSA-946h-jp5c-8fvhVendor Advisory
FAQ
What is CVE-2026-49211?
CVE-2026-49211 is a vulnerability with a CVSS score of 7.5 (HIGH). Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\EntitySearchUtil::addSearchClause() builds the LIKE expression used by the autocom...
How severe is CVE-2026-49211?
CVE-2026-49211 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-49211?
Check the references section above for vendor advisories and patch information. Affected products include: Symfony Ux.