symfony/routing is vulnerable to Open Redirect
61
Medium Risk
UrlGenerator validates route parameters by wrapping raw requirement regexes with start and end anchors. Alternation requirements are not grouped, so anchors can apply only to the first and last alternatives. Pre-fix applications can generate protocol-relative off-site URLs from values that satisfy an unanchored middle alternative. The fix groups the requirement before anchoring it.
You are affected if you are using a version that falls within the vulnerable range.
symfony/routing is vulnerable to Open Redirect in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.
Upgrade the symfony/routing and/or symfony/symfony library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant