Intel

AIKIDO-2026-10874

symfony/mailjet-mailer is vulnerable to Improper Authentication

Improper AuthenticationCVE-2026-45754 Published May 21, 2026

65

Medium Risk

This Affects:

PHPsymfony/mailjet-mailer
6.4.0 - 6.4.39
Fixed in 6.4.40
7.0.0 - 7.4.11
Fixed in 7.4.12
8.0.0 - 8.0.11
Fixed in 8.0.12
Are you affected? Scan for Free

TL;DR

Symfony webhook parsers receive configured provider secrets but do not enforce the expected webhook authentication. A forged POST to an application webhook endpoint is decoded and accepted as a provider event. Pre-fix applications can process fake delivery, bounce, spam, click, or status events. The fix requires provider-specific credentials or tokens before accepting the webhook.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

symfony/mailjet-mailer is vulnerable to Improper Authentication in versions 6.4.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.

How to fix this

Upgrade the symfony/mailjet-mailer and/or symfony/symfony library to the patch version.