Intel

AIKIDO-2026-10882

symfony/routing is vulnerable to Open Redirect

Open RedirectCVE-2026-45065 Published May 21, 2026

61

Medium Risk

This Affects:

PHPsymfony/routing
0.0.1 - 5.4.51
Fixed in 5.4.52
6.0.0 - 6.4.39
Fixed in 6.4.40
7.0.0 - 7.4.11
Fixed in 7.4.12
8.0.0 - 8.0.11
Fixed in 8.0.12
Are you affected? Scan for Free

TL;DR

UrlGenerator validates route parameters by wrapping raw requirement regexes with start and end anchors. Alternation requirements are not grouped, so anchors can apply only to the first and last alternatives. Pre-fix applications can generate protocol-relative off-site URLs from values that satisfy an unanchored middle alternative. The fix groups the requirement before anchoring it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

symfony/routing is vulnerable to Open Redirect in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.

How to fix this

Upgrade the symfony/routing and/or symfony/symfony library to the patch version.