Intel

AIKIDO-2026-10875

symfony/lox24-notifier is vulnerable to Improper Authentication

Improper AuthenticationCVE-2026-45754 Published May 21, 2026

65

Medium Risk

This Affects:

PHPsymfony/lox24-notifier
7.1.0 - 7.4.11
Fixed in 7.4.12
8.0.0 - 8.0.11
Fixed in 8.0.12
Are you affected? Scan for Free

TL;DR

Symfony webhook parsers receive configured provider secrets but do not enforce the expected webhook authentication. A forged POST to an application webhook endpoint is decoded and accepted as a provider event. Pre-fix applications can process fake delivery, bounce, spam, click, or status events. The fix requires provider-specific credentials or tokens before accepting the webhook.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

symfony/lox24-notifier is vulnerable to Improper Authentication in versions 7.1.0 - 7.4.11 and 8.0.0 - 8.0.11.

How to fix this

Upgrade the symfony/lox24-notifier library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform