Intel

AIKIDO-2026-10866

symfony/yaml is vulnerable to Uncontrolled Recursion

Uncontrolled RecursionCVE-2026-45133 Published May 21, 2026

37

Low Risk

This Affects:

PHPsymfony/yaml
0.0.1 - 5.4.51
Fixed in 5.4.52
6.0.0 - 6.4.39
Fixed in 6.4.40
7.0.0 - 7.4.11
Fixed in 7.4.12
8.0.0 - 8.0.11
Fixed in 8.0.12
Are you affected? Scan for Free

TL;DR

Parser and Inline parse nested YAML blocks, sequences, and mappings without a recursion depth limit. Deeply nested crafted YAML can exhaust the PHP stack. Pre-fix applications that parse untrusted YAML can crash worker processes. The fix tracks nesting depth in shared parser state and adds a configurable limit.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

symfony/yaml is vulnerable to Uncontrolled Recursion in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.

How to fix this

Upgrade the symfony/yaml and/or symfony/symfony library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform