diff --git a/composer.lock b/composer.lock index a59985f..99e0b9d 100644 --- a/composer.lock +++ b/composer.lock @@ -6085,16 +6085,16 @@ }, { "name": "symfony/deprecation-contracts", - "version": "v3.6.0", + "version": "v3.7.0", "source": { "type": "git", "url": "https://github.com/symfony/deprecation-contracts.git", - "reference": "63afe740e99a13ba87ec199bb07bbdee937a5b62" + "reference": "50f59d1f3ca46d41ac911f97a78626b6756af35b" }, "dist": { "type": "zip", - "url": "https://api.github.com/repos/symfony/deprecation-contracts/zipball/63afe740e99a13ba87ec199bb07bbdee937a5b62", - "reference": "63afe740e99a13ba87ec199bb07bbdee937a5b62", + "url": "https://api.github.com/repos/symfony/deprecation-contracts/zipball/50f59d1f3ca46d41ac911f97a78626b6756af35b", + "reference": "50f59d1f3ca46d41ac911f97a78626b6756af35b", "shasum": "" }, "require": { @@ -6107,7 +6107,7 @@ "name": "symfony/contracts" }, "branch-alias": { - "dev-main": "3.6-dev" + "dev-main": "3.7-dev" } }, "autoload": { @@ -6132,7 +6132,7 @@ "description": "A generic function and convention to trigger deprecation notices", "homepage": "https://symfony.com", "support": { - "source": "https://github.com/symfony/deprecation-contracts/tree/v3.6.0" + "source": "https://github.com/symfony/deprecation-contracts/tree/v3.7.0" }, "funding": [ { @@ -6143,12 +6143,16 @@ "url": "https://github.com/fabpot", "type": "github" }, + { + "url": "https://github.com/nicolas-grekas", + "type": "github" + }, { "url": "https://tidelift.com/funding/github/packagist/symfony/symfony", "type": "tidelift" } ], - "time": "2024-09-25T14:21:43+00:00" + "time": "2026-04-13T15:52:40+00:00" }, { "name": "symfony/doctrine-bridge", @@ -8274,16 +8278,16 @@ }, { "name": "symfony/polyfill-mbstring", - "version": "v1.37.0", + "version": "v1.38.2", "source": { "type": "git", "url": "https://github.com/symfony/polyfill-mbstring.git", - "reference": "6a21eb99c6973357967f6ce3708cd55a6bec6315" + "reference": "d3d318bad5e7a1bfbd026009c8bfb8d8f99ae6b6" }, "dist": { "type": "zip", - "url": "https://api.github.com/repos/symfony/polyfill-mbstring/zipball/6a21eb99c6973357967f6ce3708cd55a6bec6315", - "reference": "6a21eb99c6973357967f6ce3708cd55a6bec6315", + "url": "https://api.github.com/repos/symfony/polyfill-mbstring/zipball/d3d318bad5e7a1bfbd026009c8bfb8d8f99ae6b6", + "reference": "d3d318bad5e7a1bfbd026009c8bfb8d8f99ae6b6", "shasum": "" }, "require": { @@ -8335,7 +8339,7 @@ "shim" ], "support": { - "source": "https://github.com/symfony/polyfill-mbstring/tree/v1.37.0" + "source": "https://github.com/symfony/polyfill-mbstring/tree/v1.38.2" }, "funding": [ { @@ -8355,7 +8359,7 @@ "type": "tidelift" } ], - "time": "2026-04-10T17:25:58+00:00" + "time": "2026-05-27T06:59:30+00:00" }, { "name": "symfony/polyfill-php56", @@ -11327,16 +11331,16 @@ }, { "name": "twig/twig", - "version": "v3.24.0", + "version": "v3.27.1", "source": { "type": "git", "url": "https://github.com/twigphp/Twig.git", - "reference": "a6769aefb305efef849dc25c9fd1653358c148f0" + "reference": "ae2071bffb38f04847fc0864d730c94b9cb8ab74" }, "dist": { "type": "zip", - "url": "https://api.github.com/repos/twigphp/Twig/zipball/a6769aefb305efef849dc25c9fd1653358c148f0", - "reference": "a6769aefb305efef849dc25c9fd1653358c148f0", + "url": "https://api.github.com/repos/twigphp/Twig/zipball/ae2071bffb38f04847fc0864d730c94b9cb8ab74", + "reference": "ae2071bffb38f04847fc0864d730c94b9cb8ab74", "shasum": "" }, "require": { @@ -11391,7 +11395,7 @@ ], "support": { "issues": "https://github.com/twigphp/Twig/issues", - "source": "https://github.com/twigphp/Twig/tree/v3.24.0" + "source": "https://github.com/twigphp/Twig/tree/v3.27.1" }, "funding": [ { @@ -11403,7 +11407,7 @@ "type": "tidelift" } ], - "time": "2026-03-17T21:31:11+00:00" + "time": "2026-05-30T17:09:26+00:00" }, { "name": "webmozart/assert", diff --git a/sbom.json b/sbom.json index 57ba371..4dc5590 100644 --- a/sbom.json +++ b/sbom.json @@ -2,10 +2,10 @@ "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json", "bomFormat": "CycloneDX", "specVersion": "1.6", - "serialNumber": "urn:uuid:8ea7ef07-1d55-4a2b-b915-b6d0b514cd55", + "serialNumber": "urn:uuid:a6b5a552-2325-48aa-8d86-2e1b469f3094", "version": 1, "metadata": { - "timestamp": "2026-06-19T07:19:27+00:00", + "timestamp": "2026-06-25T21:34:37+00:00", "tools": { "components": [ { @@ -20,7 +20,7 @@ ] }, "component": { - "bom-ref": "7c1c05ea-e884-4848-ac1e-214a300b5bf4", + "bom-ref": "a2d8a023-9d75-4278-91e0-6ea6e1fef741", "type": "application", "name": ".", "properties": [ @@ -33,7 +33,7 @@ }, "components": [ { - "bom-ref": "2979e2d8-55d9-47fb-be3f-d686cb5d123d", + "bom-ref": "2f18a74b-ab19-4900-b26b-cd8d43ae5642", "type": "application", "name": "composer.lock", "properties": [ @@ -3360,10 +3360,10 @@ ] }, { - "bom-ref": "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "bom-ref": "pkg:composer/symfony/deprecation-contracts@v3.7.0", "type": "library", "name": "symfony/deprecation-contracts", - "version": "v3.6.0", + "version": "v3.7.0", "licenses": [ { "license": { @@ -3371,11 +3371,11 @@ } } ], - "purl": "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "purl": "pkg:composer/symfony/deprecation-contracts@v3.7.0", "properties": [ { "name": "aquasecurity:trivy:PkgID", - "value": "symfony/deprecation-contracts@v3.6.0" + "value": "symfony/deprecation-contracts@v3.7.0" }, { "name": "aquasecurity:trivy:PkgType", @@ -3960,10 +3960,10 @@ ] }, { - "bom-ref": "pkg:composer/symfony/polyfill-mbstring@v1.37.0", + "bom-ref": "pkg:composer/symfony/polyfill-mbstring@v1.38.2", "type": "library", "name": "symfony/polyfill-mbstring", - "version": "v1.37.0", + "version": "v1.38.2", "licenses": [ { "license": { @@ -3971,11 +3971,11 @@ } } ], - "purl": "pkg:composer/symfony/polyfill-mbstring@v1.37.0", + "purl": "pkg:composer/symfony/polyfill-mbstring@v1.38.2", "properties": [ { "name": "aquasecurity:trivy:PkgID", - "value": "symfony/polyfill-mbstring@v1.37.0" + "value": "symfony/polyfill-mbstring@v1.38.2" }, { "name": "aquasecurity:trivy:PkgType", @@ -4968,10 +4968,10 @@ ] }, { - "bom-ref": "pkg:composer/twig/twig@v3.24.0", + "bom-ref": "pkg:composer/twig/twig@v3.27.1", "type": "library", "name": "twig/twig", - "version": "v3.24.0", + "version": "v3.27.1", "licenses": [ { "license": { @@ -4979,11 +4979,11 @@ } } ], - "purl": "pkg:composer/twig/twig@v3.24.0", + "purl": "pkg:composer/twig/twig@v3.27.1", "properties": [ { "name": "aquasecurity:trivy:PkgID", - "value": "twig/twig@v3.24.0" + "value": "twig/twig@v3.27.1" }, { "name": "aquasecurity:trivy:PkgType", @@ -5090,7 +5090,7 @@ ], "dependencies": [ { - "ref": "2979e2d8-55d9-47fb-be3f-d686cb5d123d", + "ref": "2f18a74b-ab19-4900-b26b-cd8d43ae5642", "dependsOn": [ "pkg:composer/brainmaestro/composer-git-hooks@dev-master", "pkg:composer/doctrine/doctrine-bundle@2.18.2", @@ -5115,13 +5115,13 @@ "pkg:composer/symfony/mime@v7.4.9", "pkg:composer/symfony/routing@v7.4.9", "pkg:composer/symplify/easy-coding-standard@13.0.4", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { - "ref": "7c1c05ea-e884-4848-ac1e-214a300b5bf4", + "ref": "a2d8a023-9d75-4278-91e0-6ea6e1fef741", "dependsOn": [ - "2979e2d8-55d9-47fb-be3f-d686cb5d123d" + "2f18a74b-ab19-4900-b26b-cd8d43ae5642" ] }, { @@ -5130,7 +5130,7 @@ "pkg:composer/doctrine/inflector@2.1.0", "pkg:composer/psr/cache@3.0.0", "pkg:composer/psr/container@2.0.2", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/http-foundation@v7.4.8", "pkg:composer/symfony/http-kernel@v7.4.8", "pkg:composer/symfony/property-access@v7.4.8", @@ -5346,7 +5346,7 @@ "pkg:composer/symfony/filesystem@v7.4.9", "pkg:composer/symfony/finder@v7.4.8", "pkg:composer/symfony/options-resolver@v7.4.8", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0", + "pkg:composer/symfony/polyfill-mbstring@v1.38.2", "pkg:composer/symfony/polyfill-php80@v1.37.0", "pkg:composer/symfony/polyfill-php81@v1.37.0", "pkg:composer/symfony/polyfill-php84@v1.37.0", @@ -5387,7 +5387,7 @@ "ref": "pkg:composer/friendsofsymfony/jsrouting-bundle@3.6.1", "dependsOn": [ "pkg:composer/symfony/console@v7.4.9", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/framework-bundle@v7.4.9", "pkg:composer/symfony/serializer@v7.4.8", "pkg:composer/willdurand/jsonp-callback-validator@v2.0.0" @@ -5415,7 +5415,7 @@ "pkg:composer/symfony/config@v7.4.9", "pkg:composer/symfony/console@v7.4.9", "pkg:composer/symfony/dependency-injection@v7.4.9", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/event-dispatcher@v7.4.9", "pkg:composer/symfony/filesystem@v7.4.9", "pkg:composer/symfony/form@v7.4.9", @@ -5431,7 +5431,7 @@ "pkg:composer/symfony/yaml@v7.4.8", "pkg:composer/twig/intl-extra@v3.24.0", "pkg:composer/twig/string-extra@v3.24.0", - "pkg:composer/twig/twig@v3.24.0", + "pkg:composer/twig/twig@v3.27.1", "pkg:composer/willdurand/js-translation-bundle@6.1.0" ] }, @@ -5497,7 +5497,7 @@ "pkg:composer/symfony/var-dumper@v7.4.8", "pkg:composer/symfony/yaml@v7.4.8", "pkg:composer/twig/extra-bundle@v3.24.0", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { @@ -5512,7 +5512,7 @@ "pkg:composer/symfony/http-foundation@v7.4.8", "pkg:composer/symfony/http-kernel@v7.4.8", "pkg:composer/symfony/templating@v6.4.24", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { @@ -5537,7 +5537,7 @@ "pkg:composer/symfony/translation-contracts@v3.6.1", "pkg:composer/symfony/translation@v7.4.8", "pkg:composer/symfony/validator@v7.4.9", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { @@ -5579,7 +5579,7 @@ "pkg:composer/symfony/security-bundle@v7.4.8", "pkg:composer/symfony/security-csrf@v7.4.8", "pkg:composer/symfony/yaml@v7.4.8", - "pkg:composer/twig/twig@v3.24.0", + "pkg:composer/twig/twig@v3.27.1", "pkg:composer/webmozart/assert@1.12.1" ] }, @@ -5645,7 +5645,7 @@ "pkg:composer/symfony/security-http@v7.4.9", "pkg:composer/symfony/translation@v7.4.8", "pkg:composer/symfony/validator@v7.4.9", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { @@ -5662,7 +5662,7 @@ "pkg:composer/knplabs/knp-menu@v3.8.0", "pkg:composer/symfony/config@v7.4.9", "pkg:composer/symfony/dependency-injection@v7.4.9", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/http-kernel@v7.4.8" ] }, @@ -5710,7 +5710,7 @@ "pkg:composer/namshi/jose@7.2.3", "pkg:composer/symfony/config@v7.4.9", "pkg:composer/symfony/dependency-injection@v7.4.9", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/event-dispatcher@v7.4.9", "pkg:composer/symfony/http-foundation@v7.4.8", "pkg:composer/symfony/http-kernel@v7.4.8", @@ -5724,14 +5724,14 @@ "dependsOn": [ "pkg:composer/imagine/imagine@1.5.2", "pkg:composer/symfony/dependency-injection@v7.4.9", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/filesystem@v7.4.9", "pkg:composer/symfony/finder@v7.4.8", "pkg:composer/symfony/framework-bundle@v7.4.9", "pkg:composer/symfony/mime@v7.4.9", "pkg:composer/symfony/options-resolver@v7.4.8", "pkg:composer/symfony/process@v7.4.8", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { @@ -5796,7 +5796,7 @@ { "ref": "pkg:composer/pagerfanta/pagerfanta@v3.8.0", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/polyfill-php80@v1.37.0" ] }, @@ -5806,7 +5806,7 @@ "pkg:composer/symfony/config@v7.4.9", "pkg:composer/symfony/dependency-injection@v7.4.9", "pkg:composer/symfony/filesystem@v7.4.9", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0" + "pkg:composer/symfony/polyfill-mbstring@v1.38.2" ] }, { @@ -6172,7 +6172,7 @@ "pkg:composer/psr/cache@3.0.0", "pkg:composer/psr/log@3.0.2", "pkg:composer/symfony/cache-contracts@v3.6.0", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/service-contracts@v3.6.1", "pkg:composer/symfony/var-exporter@v7.4.9" ] @@ -6187,7 +6187,7 @@ { "ref": "pkg:composer/symfony/config@v7.4.9", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/filesystem@v7.4.9", "pkg:composer/symfony/polyfill-ctype@v1.37.0" ] @@ -6195,8 +6195,8 @@ { "ref": "pkg:composer/symfony/console@v7.4.9", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", + "pkg:composer/symfony/polyfill-mbstring@v1.38.2", "pkg:composer/symfony/service-contracts@v3.6.1", "pkg:composer/symfony/string@v7.4.8" ] @@ -6209,13 +6209,13 @@ "ref": "pkg:composer/symfony/dependency-injection@v7.4.9", "dependsOn": [ "pkg:composer/psr/container@2.0.2", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/service-contracts@v3.6.1", "pkg:composer/symfony/var-exporter@v7.4.9" ] }, { - "ref": "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "ref": "pkg:composer/symfony/deprecation-contracts@v3.7.0", "dependsOn": [] }, { @@ -6223,9 +6223,9 @@ "dependsOn": [ "pkg:composer/doctrine/event-manager@2.1.1", "pkg:composer/doctrine/persistence@3.4.4", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/polyfill-ctype@v1.37.0", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0", + "pkg:composer/symfony/polyfill-mbstring@v1.38.2", "pkg:composer/symfony/service-contracts@v3.6.1" ] }, @@ -6253,7 +6253,7 @@ "ref": "pkg:composer/symfony/expression-language@v7.4.8", "dependsOn": [ "pkg:composer/symfony/cache@v7.4.9", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/service-contracts@v3.6.1" ] }, @@ -6261,7 +6261,7 @@ "ref": "pkg:composer/symfony/filesystem@v7.4.9", "dependsOn": [ "pkg:composer/symfony/polyfill-ctype@v1.37.0", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0" + "pkg:composer/symfony/polyfill-mbstring@v1.38.2" ] }, { @@ -6271,12 +6271,12 @@ { "ref": "pkg:composer/symfony/form@v7.4.9", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/event-dispatcher@v7.4.9", "pkg:composer/symfony/options-resolver@v7.4.8", "pkg:composer/symfony/polyfill-ctype@v1.37.0", "pkg:composer/symfony/polyfill-intl-icu@v1.37.0", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0", + "pkg:composer/symfony/polyfill-mbstring@v1.38.2", "pkg:composer/symfony/property-access@v7.4.8", "pkg:composer/symfony/service-contracts@v3.6.1" ] @@ -6287,14 +6287,14 @@ "pkg:composer/symfony/cache@v7.4.9", "pkg:composer/symfony/config@v7.4.9", "pkg:composer/symfony/dependency-injection@v7.4.9", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/error-handler@v7.4.8", "pkg:composer/symfony/event-dispatcher@v7.4.9", "pkg:composer/symfony/filesystem@v7.4.9", "pkg:composer/symfony/finder@v7.4.8", "pkg:composer/symfony/http-foundation@v7.4.8", "pkg:composer/symfony/http-kernel@v7.4.8", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0", + "pkg:composer/symfony/polyfill-mbstring@v1.38.2", "pkg:composer/symfony/polyfill-php85@v1.37.0", "pkg:composer/symfony/routing@v7.4.9" ] @@ -6307,7 +6307,7 @@ "ref": "pkg:composer/symfony/http-client@v7.4.9", "dependsOn": [ "pkg:composer/psr/log@3.0.2", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/http-client-contracts@v3.6.0", "pkg:composer/symfony/polyfill-php83@v1.37.0", "pkg:composer/symfony/service-contracts@v3.6.1" @@ -6316,15 +6316,15 @@ { "ref": "pkg:composer/symfony/http-foundation@v7.4.8", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0" + "pkg:composer/symfony/deprecation-contracts@v3.7.0", + "pkg:composer/symfony/polyfill-mbstring@v1.38.2" ] }, { "ref": "pkg:composer/symfony/http-kernel@v7.4.8", "dependsOn": [ "pkg:composer/psr/log@3.0.2", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/error-handler@v7.4.8", "pkg:composer/symfony/event-dispatcher@v7.4.9", "pkg:composer/symfony/http-foundation@v7.4.8", @@ -6334,7 +6334,7 @@ { "ref": "pkg:composer/symfony/intl@v7.4.8", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0" + "pkg:composer/symfony/deprecation-contracts@v3.7.0" ] }, { @@ -6351,9 +6351,9 @@ { "ref": "pkg:composer/symfony/mime@v7.4.9", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/polyfill-intl-idn@v1.37.0", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0" + "pkg:composer/symfony/polyfill-mbstring@v1.38.2" ] }, { @@ -6365,7 +6365,7 @@ { "ref": "pkg:composer/symfony/options-resolver@v7.4.8", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0" + "pkg:composer/symfony/deprecation-contracts@v3.7.0" ] }, { @@ -6395,7 +6395,7 @@ "dependsOn": [] }, { - "ref": "pkg:composer/symfony/polyfill-mbstring@v1.37.0", + "ref": "pkg:composer/symfony/polyfill-mbstring@v1.38.2", "dependsOn": [] }, { @@ -6439,7 +6439,7 @@ { "ref": "pkg:composer/symfony/property-info@v7.4.8", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/string@v7.4.8", "pkg:composer/symfony/type-info@v7.4.9" ] @@ -6447,7 +6447,7 @@ { "ref": "pkg:composer/symfony/routing@v7.4.9", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0" + "pkg:composer/symfony/deprecation-contracts@v3.7.0" ] }, { @@ -6456,7 +6456,7 @@ "pkg:composer/symfony/clock@v7.4.8", "pkg:composer/symfony/config@v7.4.9", "pkg:composer/symfony/dependency-injection@v7.4.9", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/event-dispatcher@v7.4.9", "pkg:composer/symfony/http-foundation@v7.4.8", "pkg:composer/symfony/http-kernel@v7.4.8", @@ -6470,7 +6470,7 @@ { "ref": "pkg:composer/symfony/security-core@v7.4.8", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/event-dispatcher-contracts@v3.6.0", "pkg:composer/symfony/password-hasher@v7.4.8", "pkg:composer/symfony/service-contracts@v3.6.1" @@ -6485,11 +6485,11 @@ { "ref": "pkg:composer/symfony/security-http@v7.4.9", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/event-dispatcher@v7.4.9", "pkg:composer/symfony/http-foundation@v7.4.8", "pkg:composer/symfony/http-kernel@v7.4.8", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0", + "pkg:composer/symfony/polyfill-mbstring@v1.38.2", "pkg:composer/symfony/property-access@v7.4.8", "pkg:composer/symfony/security-core@v7.4.8", "pkg:composer/symfony/service-contracts@v3.6.1" @@ -6498,7 +6498,7 @@ { "ref": "pkg:composer/symfony/serializer@v7.4.8", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/polyfill-ctype@v1.37.0", "pkg:composer/symfony/polyfill-php84@v1.37.0" ] @@ -6507,7 +6507,7 @@ "ref": "pkg:composer/symfony/service-contracts@v3.6.1", "dependsOn": [ "pkg:composer/psr/container@2.0.2", - "pkg:composer/symfony/deprecation-contracts@v3.6.0" + "pkg:composer/symfony/deprecation-contracts@v3.7.0" ] }, { @@ -6519,17 +6519,17 @@ { "ref": "pkg:composer/symfony/string@v7.4.8", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/polyfill-ctype@v1.37.0", "pkg:composer/symfony/polyfill-intl-grapheme@v1.37.0", "pkg:composer/symfony/polyfill-intl-normalizer@v1.37.0", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0" + "pkg:composer/symfony/polyfill-mbstring@v1.38.2" ] }, { "ref": "pkg:composer/symfony/templating@v6.4.24", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/polyfill-ctype@v1.37.0" ] }, @@ -6540,17 +6540,17 @@ { "ref": "pkg:composer/symfony/translation@v7.4.8", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", + "pkg:composer/symfony/polyfill-mbstring@v1.38.2", "pkg:composer/symfony/translation-contracts@v3.6.1" ] }, { "ref": "pkg:composer/symfony/twig-bridge@v7.4.8", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/translation-contracts@v3.6.1", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { @@ -6558,36 +6558,36 @@ "dependsOn": [ "pkg:composer/symfony/config@v7.4.9", "pkg:composer/symfony/dependency-injection@v7.4.9", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/http-foundation@v7.4.8", "pkg:composer/symfony/http-kernel@v7.4.8", "pkg:composer/symfony/twig-bridge@v7.4.8", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { "ref": "pkg:composer/symfony/type-info@v7.4.9", "dependsOn": [ "pkg:composer/psr/container@2.0.2", - "pkg:composer/symfony/deprecation-contracts@v3.6.0" + "pkg:composer/symfony/deprecation-contracts@v3.7.0" ] }, { "ref": "pkg:composer/symfony/ux-twig-component@v2.35.0", "dependsOn": [ "pkg:composer/symfony/dependency-injection@v7.4.9", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/event-dispatcher@v7.4.9", "pkg:composer/symfony/property-access@v7.4.8", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { "ref": "pkg:composer/symfony/validator@v7.4.9", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/polyfill-ctype@v1.37.0", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0", + "pkg:composer/symfony/polyfill-mbstring@v1.38.2", "pkg:composer/symfony/polyfill-php83@v1.37.0", "pkg:composer/symfony/translation-contracts@v3.6.1" ] @@ -6595,14 +6595,14 @@ { "ref": "pkg:composer/symfony/var-dumper@v7.4.8", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0" + "pkg:composer/symfony/deprecation-contracts@v3.7.0", + "pkg:composer/symfony/polyfill-mbstring@v1.38.2" ] }, { "ref": "pkg:composer/symfony/var-exporter@v7.4.9", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0" + "pkg:composer/symfony/deprecation-contracts@v3.7.0" ] }, { @@ -6624,7 +6624,7 @@ { "ref": "pkg:composer/symfony/yaml@v7.4.8", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/polyfill-ctype@v1.37.0" ] }, @@ -6654,9 +6654,9 @@ { "ref": "pkg:composer/twig/cssinliner-extra@v3.24.0", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/tijsverkoyen/css-to-inline-styles@v2.4.0", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { @@ -6664,22 +6664,22 @@ "dependsOn": [ "pkg:composer/symfony/framework-bundle@v7.4.9", "pkg:composer/symfony/twig-bundle@v7.4.8", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { "ref": "pkg:composer/twig/inky-extra@v3.24.0", "dependsOn": [ "pkg:composer/lorenzo/pinky@1.1.0", - "pkg:composer/symfony/deprecation-contracts@v3.6.0", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/symfony/deprecation-contracts@v3.7.0", + "pkg:composer/twig/twig@v3.27.1" ] }, { "ref": "pkg:composer/twig/intl-extra@v3.24.0", "dependsOn": [ "pkg:composer/symfony/intl@v7.4.8", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { @@ -6687,15 +6687,15 @@ "dependsOn": [ "pkg:composer/symfony/string@v7.4.8", "pkg:composer/symfony/translation-contracts@v3.6.1", - "pkg:composer/twig/twig@v3.24.0" + "pkg:composer/twig/twig@v3.27.1" ] }, { - "ref": "pkg:composer/twig/twig@v3.24.0", + "ref": "pkg:composer/twig/twig@v3.27.1", "dependsOn": [ - "pkg:composer/symfony/deprecation-contracts@v3.6.0", + "pkg:composer/symfony/deprecation-contracts@v3.7.0", "pkg:composer/symfony/polyfill-ctype@v1.37.0", - "pkg:composer/symfony/polyfill-mbstring@v1.37.0" + "pkg:composer/symfony/polyfill-mbstring@v1.38.2" ] }, { @@ -6723,92 +6723,6 @@ } ], "vulnerabilities": [ - { - "id": "CVE-2026-24425", - "source": { - "name": "php-security-advisories", - "url": "https://github.com/FriendsOfPHP/security-advisories" - }, - "ratings": [ - { - "source": { - "name": "ghsa" - }, - "score": 8.8, - "severity": "high", - "method": "CVSSv31", - "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" - }, - { - "source": { - "name": "nvd" - }, - "score": 9.9, - "severity": "critical", - "method": "CVSSv31", - "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" - }, - { - "source": { - "name": "ubuntu" - }, - "severity": "medium" - } - ], - "cwes": [ - 693 - ], - "description": "Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.", - "recommendation": "Upgrade twig/twig to version 3.26.0, 3.0.0", - "advisories": [ - { - "url": "https://avd.aquasec.com/nvd/cve-2026-24425" - }, - { - "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-24425.yaml" - }, - { - "url": "https://github.com/twigphp/Twig" - }, - { - "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0" - }, - { - "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-2q52-x2ff-qgfr" - }, - { - "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24425" - }, - { - "url": "https://symfony.com/blog/cve-2026-24425-possible-sandbox-bypass-when-using-a-source-policy" - }, - { - "url": "https://symfony.com/cve-2026-24425" - }, - { - "url": "https://ubuntu.com/security/notices/USN-8408-1" - }, - { - "url": "https://www.cve.org/CVERecord?id=CVE-2026-24425" - }, - { - "url": "https://www.vulncheck.com/advisories/twig-x-x-sandbox-bypass-via-sourcepolicyinterface" - } - ], - "published": "2026-05-20T14:16:38+00:00", - "updated": "2026-06-02T00:58:58+00:00", - "affects": [ - { - "ref": "pkg:composer/twig/twig@v3.24.0", - "versions": [ - { - "version": "v3.24.0", - "status": "affected" - } - ] - } - ] - }, { "id": "CVE-2026-45063", "source": { @@ -6817,7 +6731,7 @@ }, "ratings": [], "description": "### Description\n\n`X509Authenticator` implements client-certificate (mTLS) authentication: the web server validates the client's certificate against a trusted CA, then passes the certificate's Subject DN (Distinguished Name: a string like `CN=Alice,O=Example,emailAddress=alice@example.com`) to Symfony via `$_SERVER['SSL_CLIENT_S_DN']`. Symfony extracts the user identifier from that string.\n\nThe extraction uses an **unanchored** regex that matches `emailAddress=` anywhere in the DN string: including inside the *value* of a different RDN (Relative Distinguished Name: one `key=value` component of the DN), such as `CN`. An attacker who can obtain a certificate from a trusted CA with a free-text `CN` can smuggle `emailAddress=victim@target` inside the CN value and be authenticated as the victim.\n\n### Resolution\n\nThe `X509Authenticator` now uses a regex that anchors the match to an RDN boundary (start of string, or following a `,` / `/` separator).\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/ccb3f724c7ff55670a6fe3521c7bf1514cceb478) for branch 5.4.\n\n### Credits\n\nSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.", - "recommendation": "Upgrade symfony/security-http to version 3.0.0, 5.4.52, 6.3.0, 7.4.12, 6.2.0, 6.4.40, 7.2.0, 7.3.0, 5.0.0, 5.2.0, 5.4.0, 6.1.0, 7.1.0, 7.4.0, 4.0.0, 5.1.0, 5.3.0, 6.4.0, 8.0.12", + "recommendation": "Upgrade symfony/security-http to version 5.2.0, 7.1.0, 3.0.0, 5.1.0, 5.4.0, 6.3.0, 6.4.0, 7.2.0, 7.4.0, 8.0.12, 5.3.0, 5.4.52, 6.1.0, 7.3.0, 7.4.12, 4.0.0, 5.0.0, 6.2.0, 6.4.40", "advisories": [ { "url": "https://avd.aquasec.com/nvd/cve-2026-45063" @@ -6868,7 +6782,7 @@ } ], "description": "### Description\n\nSymfony routes can declare a requirements regex per path parameter, e.g. a route `/{_locale}/blog` with `requirements: { _locale: 'en|fr|de' }`. The Twig `path()` / `url()` helpers (backed by `UrlGenerator`) validate supplied parameter values against that regex before building the URL.\n\nUrlGenerator constructs the validation pattern as `'#^'.$req.'$#'`, where `$req` is the raw requirement string. For a requirement expressed as an alternation, e.g. `_locale: 'ar|bg|...|vi|...|zh_CN'` (very common), `^` and `$` anchor only the first and last alternatives, so any middle alternative matches as an unanchored substring. A value like `/evil.com` satisfies the requirement (because it contains `vi`), and the generated path becomes `//evil.com/...`: a protocol-relative URL the browser navigates off-site.\n\n### Resolution\n\nThe `UrlGenerator` class now wraps the requirement in a non-capturing group so the `^` and `$` anchors apply to the whole alternation.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/bcf487c22f3240ba994124e0e0fe8616f3cfc47a) for branch 5.4.\n\n### Credits\n\nSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.", - "recommendation": "Upgrade symfony/routing to version 4.0.0, 5.0.0, 5.1.0, 6.3.0, 5.4.0, 6.2.0, 6.4.40, 7.4.0, 5.2.0, 5.4.52, 6.1.0, 6.4.0, 7.2.0, 7.3.0, 8.0.12, 3.0.0, 5.3.0, 7.1.0, 7.4.12", + "recommendation": "Upgrade symfony/routing to version 5.0.0, 5.1.0, 6.4.40, 7.4.0, 7.4.12, 8.0.12, 5.3.0, 6.2.0, 6.3.0, 6.4.0, 7.2.0, 7.1.0, 3.0.0, 5.2.0, 5.4.0, 5.4.52, 6.1.0, 7.3.0, 4.0.0", "advisories": [ { "url": "https://avd.aquasec.com/nvd/cve-2026-45065" @@ -6912,7 +6826,7 @@ }, "ratings": [], "description": "### Description\n\n`Symfony\\Component\\Mime\\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers treat it as a security boundary.\n\nThe constructor accepts email addresses whose local-part (the part before `@`) is an RFC-5322 *quoted string* containing raw `\\r\\n` bytes, e.g. `\"x\\r\\nBcc: attacker@evil\"@example.com`. The stored address is later emitted verbatim into (1) the rendered message headers and (2) `SmtpTransport`'s `MAIL FROM:<...>` / `RCPT TO:<...>` protocol lines, turning the embedded CRLF into a new mail header and/or a new SMTP command.\n\n### Resolution\n\nThe `Address` constructor now rejects addresses containing line breaks.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/dc2dbd29211eb4ddc451373fa1374fb926e94604) for branch 5.4.\n\n### Credits\n\nWe would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.", - "recommendation": "Upgrade symfony/mime to version 3.0.0, 5.1.0, 5.4.0, 6.4.0, 7.4.0, 4.0.0, 5.3.0, 6.1.0, 6.2.0, 7.1.0, 7.4.12, 5.2.0, 6.3.0, 6.4.40, 7.3.0, 5.0.0, 5.4.52, 7.2.0, 8.0.12", + "recommendation": "Upgrade symfony/mime to version 7.4.0, 4.0.0, 7.2.0, 7.4.12, 5.0.0, 5.4.0, 6.1.0, 6.2.0, 6.4.40, 8.0.12, 5.1.0, 5.2.0, 5.4.52, 6.3.0, 7.1.0, 7.3.0, 3.0.0, 5.3.0, 6.4.0", "advisories": [ { "url": "https://avd.aquasec.com/nvd/cve-2026-45067" @@ -6956,7 +6870,7 @@ }, "ratings": [], "description": "### Description\n\nSymfony Mailer selects a transport via the `MAILER_DSN` environment variable / configuration (e.g. `smtp://...`, `sendmail://...`, `native://default`). `SendmailTransport` invokes the local `sendmail` binary and supports two modes: `-bs` (speak SMTP over stdin: the default) and `-t` (read the message on stdin, pass recipients as command-line arguments).\n\nIn `-t` mode, recipient addresses are appended to the sendmail command line **without a `--` end-of-options separator**. A recipient address beginning with `-` (which `Symfony\\Component\\Mime\\Address` accepts as valid) is therefore interpreted by sendmail as a command-line option rather than an address.\n\n### Resolution\n\nThe `SendmailTransport` transport now ensure `--` is set before the list of recipients.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/c45144862dc289d03952f41f6078174089a3afc6) for branch 5.4.\n\n### Credits\n\nSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.", - "recommendation": "Upgrade symfony/mailer to version 7.2.0, 7.3.0, 5.1.0, 6.2.0, 6.4.40, 7.4.0, 7.4.12, 8.0.12, 3.0.0, 4.0.0, 5.3.0, 5.4.0, 5.4.52, 6.3.0, 5.2.0, 6.1.0, 5.0.0, 6.4.0, 7.1.0", + "recommendation": "Upgrade symfony/mailer to version 4.0.0, 5.0.0, 5.3.0, 6.3.0, 6.4.40, 3.0.0, 6.2.0, 6.4.0, 7.1.0, 7.3.0, 8.0.12, 5.1.0, 5.2.0, 5.4.52, 7.2.0, 7.4.12, 5.4.0, 6.1.0, 7.4.0", "advisories": [ { "url": "https://avd.aquasec.com/nvd/cve-2026-45068" @@ -7044,7 +6958,7 @@ }, "ratings": [], "description": "### Description\n\n`Symfony\\Component\\Mime\\Header\\ParameterizedHeader` (and the related parameter handling reachable from `Symfony\\Component\\Mime\\Header\\Headers`) is responsible for serializing structured headers such as `Content-Type` and `Content-Disposition`, which carry `key=value` parameters (e.g. `Content-Disposition: attachment; filename=\"x\"`).\n\nRFC 2045 / RFC 5322 require parameter *names* to be `tokens`: a restricted ASCII subset that excludes whitespace, CR/LF, and the `tspecials` set. Symfony's parameter handling validates and properly encodes parameter *values*, but does not validate parameter *names*: the supplied name is emitted verbatim into the serialized header.\n\nA caller that derives a parameter name from untrusted input, e.g. an application that lets a user influence a `Content-Disposition` parameter name, can include `\\r\\n` or other non-token bytes inside the name, terminating the current header and injecting additional headers in the rendered message. This is the classic CRLF / header-injection primitive applied to the parameter-name slot.\n\n### Resolution\n\n`ParameterizedHeader` now rejects parameter names that contain bytes outside the RFC `token` character class.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/e62ea217f8b4ca8ae922ad0f949e0c4dc1f9b613) for branch 5.4.\n\n### Credits\n\nSymfony would like to thank Fabian Fleischer for reporting the issue and Alexandre Daubois for fixing it.", - "recommendation": "Upgrade symfony/mime to version 4.0.0, 5.2.0, 5.3.0, 6.1.0, 6.4.0, 6.4.40, 7.3.0, 8.0.12, 3.0.0, 5.4.0, 6.2.0, 7.1.0, 7.4.0, 7.4.12, 5.0.0, 5.1.0, 5.4.52, 6.3.0, 7.2.0", + "recommendation": "Upgrade symfony/mime to version 5.2.0, 5.4.52, 6.1.0, 6.4.40, 5.3.0, 5.4.0, 7.3.0, 7.4.0, 7.4.12, 6.2.0, 6.3.0, 6.4.0, 7.1.0, 7.2.0, 8.0.12, 3.0.0, 4.0.0, 5.0.0, 5.1.0", "advisories": [ { "url": "https://avd.aquasec.com/nvd/cve-2026-45070" @@ -7085,7 +6999,7 @@ }, "ratings": [], "description": "### Description\n\n`Symfony\\Component\\Cache\\Adapter\\PdoAdapter` is the PDO-backed cache adapter. Its `clear($prefix)` method (inherited from `AbstractAdapterTrait`) is documented to delete cache items whose key starts with `$prefix`.\n\nIn the non-versioning code path, the caller-supplied `$prefix` is concatenated into `$namespace = $this->namespace.$prefix` and passed to `PdoAdapter::doClear()`, which builds:\n\n```sql\nDELETE FROM WHERE LIKE '%'\n```\n\nThe value is interpolated directly into the SQL text and executed with `PDO::exec()`: `$namespace` is not bound. A caller able to influence `$prefix` can break out of the literal and inject SQL, expanding deletion scope from the intended prefix to arbitrary rows, or otherwise reshape query semantics.\n\nMost applications don't expose `clear($prefix)` to untrusted input directly, but the contract of the method is to safely accept any prefix string, so the lack of escaping is a defect of the adapter itself.\n\n### Resolution\n\n`AbstractAdapterTrait::clear()` now rejects any `$prefix` containing characters outside `[-+.A-Za-z0-9]`: when an invalid prefix is supplied, the method logs a warning and returns `false` instead of reaching the SQL layer. This blocks quotes, `%`, null bytes and other characters that would let an attacker break out of the `LIKE` literal.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/ec50b799d79ebe24561f29351c1efcb6da95c9b1) for branch 5.4.\n\n### Credits\nSymfony would like to thank secsys_codex for reporting the issue and Nicolas Grekas for fixing it.", - "recommendation": "Upgrade symfony/cache to version 3.0.0, 5.0.0, 5.2.0, 5.4.0, 5.4.52, 7.3.0, 7.4.12, 8.0.12, 4.0.0, 6.3.0, 7.1.0, 7.4.0, 6.4.0, 5.3.0, 6.1.0, 6.2.0, 5.1.0, 6.4.40, 7.2.0", + "recommendation": "Upgrade symfony/cache to version 6.1.0, 6.4.0, 7.4.0, 5.2.0, 5.4.0, 6.4.40, 3.0.0, 5.1.0, 6.2.0, 6.3.0, 7.1.0, 7.3.0, 7.4.12, 5.0.0, 7.2.0, 8.0.12, 4.0.0, 5.3.0, 5.4.52", "advisories": [ { "url": "https://avd.aquasec.com/nvd/cve-2026-45073" @@ -7129,7 +7043,7 @@ }, "ratings": [], "description": "`Cas2Handler` builds this `service` parameter from `Request::getSchemeAndHttpHost()`, which reflects the attacker-controlled HTTP `Host` header whenever Symfony's `framework.trusted_hosts` setting is not configured (the default). An attacker who controls any *other* application registered with the same CAS server can replay a victim's ticket against the Symfony application, with a spoofed `Host` header, and be authenticated as that victim.\n\n### Resolution\n\nA new required `service_url` configuration option is introduced on `Cas2Handler`. The CAS `service` parameter sent to the validation endpoint is now built from this configured URL instead of being derived from the request's `Host` header, preventing cross-service ticket replay via Host header spoofing.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/5ba145dba702404801bdf9e7e8d6df170060d541) for branch 7.4.\n\n### Credits\n\nSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and Nicolas Grekas for providing the fix.", - "recommendation": "Upgrade symfony/security-http to version 7.2.0, 7.3.0, 7.4.0, 7.4.12, 8.0.12", + "recommendation": "Upgrade symfony/security-http to version 7.4.12, 8.0.12, 7.2.0, 7.3.0, 7.4.0", "advisories": [ { "url": "https://avd.aquasec.com/nvd/cve-2026-45074" @@ -7221,257 +7135,6 @@ } ] }, - { - "id": "CVE-2026-46633", - "source": { - "name": "php-security-advisories", - "url": "https://github.com/FriendsOfPHP/security-advisories" - }, - "ratings": [], - "description": "### Description\n\n`Compiler::string()` escapes `\"`, `$`, `\\`, NUL and TAB when generating PHP double-quoted string literals, but does not escape single quotes. In `ModuleNode::compileConstructor()`, the template name from a `{% use %}` tag is compiled via `subcompile()` -> `string()` and placed inside a surrounding PHP single-quoted string literal. A template name containing a single quote terminates that surrounding string early, allowing arbitrary PHP expressions to be injected into the compiled cache file.\n\nThe injected code executes within the PHP process when the cache file is first loaded, bypassing the Twig sandbox entirely and achieving remote code execution. `SecurityPolicy` unconditionally allows `{% use %}` regardless of the configured `allowedTags`, so this primitive is reachable from sandboxed templates as well.\n\n### Resolution\n\n`Compiler::string()` now also escapes single quotes so that template names placed inside single-quoted PHP literals can no longer break out of the surrounding context.\n\n### Credits\n\nTwig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting the issue and providing the fix.", - "recommendation": "Upgrade twig/twig to version 2.0.0, 3.0.0, 3.26.0", - "advisories": [ - { - "url": "https://avd.aquasec.com/nvd/cve-2026-46633" - }, - { - "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46633.yaml" - }, - { - "url": "https://github.com/twigphp/Twig" - }, - { - "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-7p85-w9px-jpjp" - }, - { - "url": "https://symfony.com/cve-2026-46633" - } - ], - "affects": [ - { - "ref": "pkg:composer/twig/twig@v3.24.0", - "versions": [ - { - "version": "v3.24.0", - "status": "affected" - } - ] - } - ] - }, - { - "id": "CVE-2026-46634", - "source": { - "name": "php-security-advisories", - "url": "https://github.com/FriendsOfPHP/security-advisories" - }, - "ratings": [ - { - "source": { - "name": "ghsa" - }, - "severity": "medium" - } - ], - "description": "### Description\n\nWhen the sandbox is enabled selectively via `SourcePolicyInterface` (and not globally), a sandboxed template that is allowed to call `template_from_string` and `include` can render an arbitrary inner template with no security policy enforcement.\n\n`Environment::createTemplate()` compiles the inner string under a synthesized name (`__string_template__`), so a name/path-based `SourcePolicy` returns `false` for it, and the inner template's `checkSecurity()` becomes a no-op. From a template the integrator believes is sandboxed, an attacker can use any tag/filter/function (including `constant()` to read secrets, or `|map(\"system\")` to execute shell commands).\n\n### Resolution\n\nThis is a configuration trap rather than a code bug: there is no legitimate use case for exposing `template_from_string` to untrusted template authors, and propagating the parent sandbox state through `template_from_string` would require invasive changes to `SourcePolicyInterface` semantics with their own risks.\n\nStarting with Twig 3.26.0, the documentation and the PHPDoc of `StringLoaderExtension::templateFromString()` explicitly warn against allowing `template_from_string` in a sandboxed environment (i.e. listing it in a `SecurityPolicy` allowed-functions list). Integrators using a `SourcePolicyInterface` MUST NOT allow `template_from_string` in their allowed functions; the safest option is not to register `StringLoaderExtension` at all when a sandbox is in use.\n\n### Credits\n\nTwig would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue.", - "recommendation": "Upgrade twig/twig to version 3.26.0", - "advisories": [ - { - "url": "https://avd.aquasec.com/nvd/cve-2026-46634" - }, - { - "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46634.yaml" - }, - { - "url": "https://github.com/twigphp/Twig" - }, - { - "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-24x9-r6q4-q93w" - }, - { - "url": "https://symfony.com/cve-2026-46634" - } - ], - "affects": [ - { - "ref": "pkg:composer/twig/twig@v3.24.0", - "versions": [ - { - "version": "v3.24.0", - "status": "affected" - } - ] - } - ] - }, - { - "id": "CVE-2026-46638", - "source": { - "name": "php-security-advisories", - "url": "https://github.com/FriendsOfPHP/security-advisories" - }, - "ratings": [], - "description": "### Description\n\nThe fix for CVE-2024-45411 / GHSA-6j75-5wfj-gh66 added an explicit `$loaded->unwrap()->checkSecurity()` call in `CoreExtension::include()` so that a template already cached in `Environment::$loadedTemplates` is re-checked when included with `sandboxed = true`.\n\nThe deprecated but still functional `{% sandbox %}{% include ... %}{% endsandbox %}` tag path was not updated: it compiles to `enableSandbox(); yield from $this->load(...)->unwrap()->yield(...); disableSandbox();` with no `checkSecurity()` re-invocation. If the included template was loaded once outside the sandbox in the same `Environment` instance, its constructor (and therefore its compiled `checkSecurity()` call) already ran while `isSandboxed()` was `false`, so the tags/filters/functions allowlist enforced by `SecurityPolicy::checkSecurity()` is never applied.\n\nAn attacker who can author the included template gains access to every filter, function and tag registered in the environment, regardless of the sandbox policy.\n\n### Resolution\n\nThe compiled output of `{% sandbox %}{% include %}` now calls `checkSecurity()` on the loaded template, matching the behaviour of `CoreExtension::include()` with `sandboxed = true`.\n\n### Credits\n\nTwig would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.", - "recommendation": "Upgrade twig/twig to version 2.0.0, 3.0.0, 3.26.0", - "advisories": [ - { - "url": "https://avd.aquasec.com/nvd/cve-2026-46638" - }, - { - "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46638.yaml" - }, - { - "url": "https://github.com/advisories/GHSA-6j75-5wfj-gh66" - }, - { - "url": "https://github.com/twigphp/Twig" - }, - { - "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-7fxw-r6jv-74c8" - }, - { - "url": "https://symfony.com/cve-2026-46638" - } - ], - "affects": [ - { - "ref": "pkg:composer/twig/twig@v3.24.0", - "versions": [ - { - "version": "v3.24.0", - "status": "affected" - } - ] - } - ] - }, - { - "id": "CVE-2026-46639", - "source": { - "name": "php-security-advisories", - "url": "https://github.com/FriendsOfPHP/security-advisories" - }, - "ratings": [], - "description": "### Description\n\nThe object-destructuring assignment syntax introduced in Twig 3.24.0 generates a call to `CoreExtension::getAttribute()` with the `$sandboxed` argument hardcoded to `false`, regardless of whether a `SandboxExtension` is active. This permanently disables the sandbox's property and method policy checks for every destructuring expression.\n\n`ObjectDestructuringSetBinary::compile()` emits:\n\n```php\nCoreExtension::getAttribute($this->env, $this->source, ..., \\Twig\\Template::ANY_CALL, false, false, false, ...);\n// ^^^^^\n// sandbox check never runs\n```\n\nWhereas `GetAttrExpression::compile()` correctly passes `$env->hasExtension(SandboxExtension::class)`.\n\nAn attacker with write access to a sandboxed Twig template can read any public property or invoke any public getter on objects passed to the template engine, bypassing `SecurityPolicy` restrictions. The exploit requires only the `{% do %}` tag to be in `allowedTags`, which is a common configuration.\n\n### Resolution\n\nThe destructuring compiler now forwards the active sandbox flag to `getAttribute()` so property/method allowlists are enforced.\n\n### Credits\n\nTwig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue.", - "recommendation": "Upgrade twig/twig to version 3.26.0", - "advisories": [ - { - "url": "https://avd.aquasec.com/nvd/cve-2026-46639" - }, - { - "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46639.yaml" - }, - { - "url": "https://github.com/twigphp/Twig" - }, - { - "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-mm6w-gr99-p3jj" - }, - { - "url": "https://symfony.com/cve-2026-46639" - } - ], - "affects": [ - { - "ref": "pkg:composer/twig/twig@v3.24.0", - "versions": [ - { - "version": "v3.24.0", - "status": "affected" - } - ] - } - ] - }, - { - "id": "CVE-2026-46640", - "source": { - "name": "php-security-advisories", - "url": "https://github.com/FriendsOfPHP/security-advisories" - }, - "ratings": [], - "description": "### Description\n\nThe `obj.(expr)` dynamic-attribute syntax (added in 3.15.0 as the replacement for the deprecated `attribute()` function) lets the attribute be an arbitrary expression. When the receiver is `_self` (or any `{% import %}` alias) and the parenthesised expression is a string literal, `DotExpressionParser` short-circuits to the macro-call path and concatenates the attacker-controlled string into a `MacroReferenceExpression` name with no identifier validation. `MacroReferenceExpression::compile()` then emits that name raw into the generated PHP source.\n\nAn attacker who can supply template source can inject arbitrary PHP into the compiled template and execute it at template-load time, before `checkSecurity()` is ever called. This is a complete bypass of `SandboxExtension`, including a globally-enabled sandbox with an empty `SecurityPolicy` allowlist.\n\n### Resolution\n\nThe parser now validates that the dynamic attribute resolves to a valid macro identifier before routing through `MacroReferenceExpression`, and the macro-reference compiler emits the name through a properly escaped path.\n\n### Credits\n\nTwig would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.", - "recommendation": "Upgrade twig/twig to version 3.26.0", - "advisories": [ - { - "url": "https://avd.aquasec.com/nvd/cve-2026-46640" - }, - { - "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46640.yaml" - }, - { - "url": "https://github.com/twigphp/Twig" - }, - { - "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-45vw-wh46-2vx8" - }, - { - "url": "https://github.com/vladko312/extras/blob/main/CVE-2026-46640.py" - }, - { - "url": "https://symfony.com/cve-2026-46640" - } - ], - "affects": [ - { - "ref": "pkg:composer/twig/twig@v3.24.0", - "versions": [ - { - "version": "v3.24.0", - "status": "affected" - } - ] - } - ] - }, - { - "id": "CVE-2026-47732", - "source": { - "name": "php-security-advisories", - "url": "https://github.com/FriendsOfPHP/security-advisories" - }, - "ratings": [ - { - "source": { - "name": "ghsa" - }, - "severity": "high" - } - ], - "description": "### Description\n\n`SandboxNodeVisitor` enforces `SecurityPolicy::checkMethodAllowed()` for implicit `__toString()` calls by wrapping selected AST nodes in `CheckToStringNode`. The set of wrapped nodes is incomplete, and several Twig language constructs still trigger PHP string coercion on a `Stringable` operand without first consulting the policy. A sandboxed template author can therefore invoke `__toString()` on any object reachable in the render context, even when `__toString` on its class is not allowlisted.\n\nConfirmed bypass vectors:\n\n- Conditional expressions (`a ? b : c`, `a ?: b`, `a ?? b`) used as the input of a string-coercing filter or as a filter/function argument.\n- The `matches` operator and the loose comparison operators (`==`, `!=`, `<`, `>`, `<=`, `>=`, `<=>`), which coerce a `Stringable` operand to string and can be used as an oracle to recover the value byte by byte (no tag, filter or function needs to be allowlisted).\n- Twig tests in general (which were never policy-gated), in particular `is empty` which casts a `Stringable` value via `(string) $value` in `CoreExtension::testEmpty()`.\n- Null-coalesce expressions nested in concatenation, and the direct output of allowed functions or filters that return a `Stringable` object.\n- Arguments passed to allowed object methods, template-name expressions of template-loading tags (`include`, `extends`, `use`, ...), dynamic attribute/property names, and spread arguments from `Traversable` objects.\n- The `do` tag and the `..` range operator.\n\n### Resolution\n\nThe sandbox now wraps every child node that the parent will string-coerce at runtime, instead of relying on a hardcoded list of node types in `SandboxNodeVisitor`. A new `Twig\\Node\\CoercesChildrenToStringInterface` lets nodes declare which of their children must be guarded; core nodes (concatenation, comparison and range binaries, filter/function/test expressions, `do`, `include`, `extends`, `use`, ...) implement it. Spread arguments are materialised and policy-checked via the new `SandboxExtension::ensureSpreadAllowed()`, and dynamic attribute names are checked at runtime inside `CoreExtension::getAttribute()`.\n\n### Credits\n\nTwig would like to thank Anthropic Glasswing and El Kharoubi Iosif for reporting the issues, and Fabien Potencier for providing the fixes.", - "recommendation": "Upgrade twig/twig to version 2.0.0, 3.0.0, 3.26.0", - "advisories": [ - { - "url": "https://avd.aquasec.com/nvd/cve-2026-47732" - }, - { - "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-47732.yaml" - }, - { - "url": "https://github.com/twigphp/Twig" - }, - { - "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0" - }, - { - "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-pr2w-4gpj-cpq4" - }, - { - "url": "https://symfony.com/cve-2026-47732" - } - ], - "affects": [ - { - "ref": "pkg:composer/twig/twig@v3.24.0", - "versions": [ - { - "version": "v3.24.0", - "status": "affected" - } - ] - } - ] - }, { "id": "CVE-2026-48489", "source": { @@ -7487,7 +7150,7 @@ } ], "description": "### Description\n\nWhen a firewall is configured with `form-login` (or any authenticator using `DefaultAuthenticationFailureHandler`) and the `failure_forward: true` option, the handler reads the `_failure_path` parameter from the failing login request and uses it as the path of an internal subrequest dispatched through `HttpKernelInterface::SUB_REQUEST`.\n\nSymfony's `Firewall::onKernelRequest` listener intentionally skips subrequests under the assumption they are internally generated and trusted, which also means `AccessListener` (the listener that evaluates `access_control`) does not run. Because the attacker controls the target of the subrequest, an unauthenticated POST to the check path with `_failure_path=/admin/whatever` performs a local request forgery that executes the target controller outside the firewall perimeter and returns its response to the caller.\n\nApplications that follow Symfony's recommended best practice of protecting administrative areas with broad `access_control` rules (e.g. `^/admin` requires `ROLE_ADMIN`) and expose read-only GET endpoints under that area (data exports, internal APIs, account views) are fully exposed: any such GET route can be read by an unauthenticated attacker without any developer misconfiguration, debug mode, or state-changing GET handler being required.\n\n### Resolution\n\n`DefaultAuthenticationFailureHandler` no longer honors the request-supplied `_failure_path` parameter when `failure_forward` is enabled. The subrequest is always dispatched to the configured `failure_path` option (defaulting to `login_path`), which is set by the application owner and not by the request. The redirect branch (`failure_forward: false`) is unchanged because redirects re-enter the firewall on the next request and are not subject to this bypass.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/c48a4276309e11aedeeb0ce3a89dfbf0b4fe04ff) for branch 5.4.\n\n### Credits\n\nSymfony would like to thank Nguyen Ngoc Toan Thang (@a-tt-om) and Tran Quoc Tri Trung (@teebow1e) for reporting the issue, and Nicolas Grekas for providing the fix.", - "recommendation": "Upgrade symfony/security-http to version 5.4.53, 6.3.0, 6.4.0, 7.3.0, 3.0.0, 6.1.0, 7.4.13, 4.0.0, 5.0.0, 5.4.0, 5.1.0, 5.3.0, 6.2.0, 6.4.41, 7.1.0, 7.2.0, 7.4.0, 8.0.13, 5.2.0", + "recommendation": "Upgrade symfony/security-http to version 6.4.0, 6.4.41, 7.1.0, 7.3.0, 8.0.13, 5.2.0, 6.1.0, 7.4.13, 3.0.0, 4.0.0, 7.4.0, 5.0.0, 5.3.0, 6.2.0, 6.3.0, 7.2.0, 5.1.0, 5.4.0, 5.4.53", "advisories": [ { "url": "https://avd.aquasec.com/nvd/cve-2026-48489" @@ -7581,7 +7244,7 @@ }, "ratings": [], "description": "### Description\n\n`Symfony\\Component\\Routing\\Generator\\UrlGenerator::doGenerate()` percent-encodes `.` and `..` path segments so that the generated URL still resolves to the originating route after RFC 3986 §5.2.4 dot-segment removal (which strict RFC-3986 consumers — routers, reverse proxies, HTTP clients — perform *before* percent-decoding).\n\nThe encoding was implemented as `strtr($url, ['/../' => '/%2E%2E/', '/./' => '/%2E/'])` plus a trailing-segment fixup. `strtr` advances past the trailing `/` of each match, so the next dot-segment in a chained sequence was left unescaped:\n\n| Input | Output (before fix) | Expected |\n| -------------------- | ---------------------------------------- | ----------------------------------- |\n| `/../../../` | `/%2E%2E/../%2E%2E/` | `/%2E%2E/%2E%2E/%2E%2E/` |\n| `/foo/../../../bar` | `/foo/%2E%2E/../%2E%2E/bar` | `/foo/%2E%2E/%2E%2E/%2E%2E/bar` |\n\nWhen a route exposes a parameter constrained by a permissive requirement (`.+`, `.*`, or similar) that accepts dots and slashes, attacker-controlled chained `..` or `.` segments produce a generated URL that, under strict RFC 3986 normalization, collapses to a different path than the originating route. The Twig `path()` / `url()` helpers and any server-side use of `UrlGenerator` are affected. Same class of route round-trip integrity issue as CVE-2026-45065.\n\nNote: WHATWG-conformant browsers treat `%2E`/`%2E%2E` as dot-segments during URL parsing, so the encoding never protected browser-side traversal. The defense exists for RFC-3986-conformant consumers; restoring it for chained segments closes the gap there.\n\n### Resolution\n\n`UrlGenerator` now matches every `/.` or `/..` dot-segment in a single left-to-right `preg_replace_callback` pass using a lookahead that does not consume the trailing `/`, so adjacent dot-segments are encoded correctly.\n\nThe patches for this issue are available [here](https://github.com/symfony/symfony/commit/4b63c3a3f7af04ecd79c89a594b0b02a01990b1d) for branch 5.4 (and forward-ported to 6.4, 7.4, 8.0 and 8.1).\n\n### Credits\n\nSymfony would like to thank Alex Pott for reporting the issue and Nicolas Grekas for providing the fix.", - "recommendation": "Upgrade symfony/routing to version 6.4.41, 5.3.0, 5.4.0, 6.1.0, 6.3.0, 6.4.0, 7.4.0, 5.4.53, 6.2.0, 7.2.0, 7.4.13, 7.1.0, 3.0.0, 4.0.0, 5.2.0, 7.3.0, 8.0.13, 5.0.0, 5.1.0", + "recommendation": "Upgrade symfony/routing to version 7.3.0, 4.0.0, 5.2.0, 5.4.0, 6.3.0, 7.4.0, 3.0.0, 5.3.0, 5.4.53, 6.4.41, 7.4.13, 8.0.13, 6.1.0, 6.2.0, 5.0.0, 5.1.0, 6.4.0, 7.1.0, 7.2.0", "advisories": [ { "url": "https://avd.aquasec.com/nvd/cve-2026-48784"