Intel

AIKIDO-2026-10868

symfony/yaml is vulnerable to Regular Expression Denial of Service (ReDoS)

Regular Expression Denial of Service (ReDoS)CVE-2026-45305 Published May 21, 2026

37

Low Risk

This Affects:

PHPsymfony/yaml
0.0.1 - 5.4.51
Fixed in 5.4.52
6.0.0 - 6.4.39
Fixed in 6.4.40
7.0.0 - 7.4.11
Fixed in 7.4.12
8.0.0 - 8.0.11
Fixed in 8.0.12
Are you affected? Scan for Free

TL;DR

Parser::cleanup() uses regular expressions with overlapping quantifiers while stripping YAML directives and markers. Crafted leading YAML content can trigger catastrophic backtracking. Pre-fix applications that parse untrusted YAML can spend excessive CPU during cleanup. The fix rewrites the cleanup expressions with unambiguous, non-backtracking patterns.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

symfony/yaml is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.

How to fix this

Upgrade the symfony/yaml and/or symfony/symfony library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform