Vulnerability Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the slot identifier (props vs propsFromParent), or request context, allowing a signed blob minted for one component or slot to be replayed in another and set a read-only prop on a target component. This issue is fixed in versions 2.36.0 and 3.1.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symfony | Ux | >= 2.8.0, < 2.36.0 |
Related Weaknesses (CWE)
References
- https://github.com/symfony/ux/commit/a224b5af3e2e33ee14ac71356ae0e0877900a81cPatch
- https://github.com/symfony/ux/releases/tag/v2.36.0Release Notes
- https://github.com/symfony/ux/releases/tag/v3.1.0Release Notes
- https://github.com/symfony/ux/security/advisories/GHSA-34w5-c283-j9fgVendor Advisory
FAQ
What is CVE-2026-49212?
CVE-2026-49212 is a vulnerability with a CVSS score of 7.5 (HIGH). Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop key/value pairs and di...
How severe is CVE-2026-49212?
CVE-2026-49212 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-49212?
Check the references section above for vendor advisories and patch information. Affected products include: Symfony Ux.