symfony/twilio-notifier is vulnerable to Missing Authentication
65
Medium Risk
TwilioRequestParser receives the configured webhook secret but does not verify the X-Twilio-Signature header. A forged POST to an application webhook endpoint is decoded and accepted as a Twilio callback. Pre-fix applications can process fake delivery, failure, or status events. The fix verifies the Twilio HMAC signature before parsing the webhook payload.
You are affected if you are using a version that falls within the vulnerable range.
symfony/twilio-notifier is vulnerable to Missing Authentication in versions 6.4.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.
Upgrade the symfony/twilio-notifier and/or symfony/symfony library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant