Defines an object-oriented layer for the HTTP specification
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10963 symfony/http-foundation is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.4.0 - 6.4.40, 7.0.0 - 7.4.12 and 8.0.0 - 8.0.12. | 6.4.0 - 6.4.407.0.0 - 7.4.128.0.0 - 8.0.12 | Medium |
AIKIDO-2025-10807 symfony/http-foundation is vulnerable to Authorization Bypass in versions 2.0.0 - 5.4.49, 6.0.0 - 6.4.28 and 7.0.0 - 7.3.6. | 2.0.0 - 5.4.496.0.0 - 6.4.287.0.0 - 7.3.6 | High |
CVE-2024-50345 symfony/http-foundation is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 0.0.0 - 5.4.46, 6.0.0 - 6.4.14 and 7.0.0 - 7.1.7. | 0.0.0 - 5.4.466.0.0 - 6.4.147.0.0 - 7.1.7 | Low |
CVE-2015-2309 symfony/http-foundation is vulnerable to Improper Input Validation in versions 2.0.0 - 2.3.27, 2.4.0 - 2.5.11 and 2.6.0 - 2.6.6. | 2.0.0 - 2.3.272.4.0 - 2.5.112.6.0 - 2.6.6 | Medium |
CVE-2014-6061 symfony/http-foundation is vulnerable to Improper Input Validation in versions 2.0.0 - 2.3.19, 2.4.0 - 2.4.9 and 2.5.0 - 2.5.4. | 2.0.0 - 2.3.192.4.0 - 2.4.92.5.0 - 2.5.4 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-mbstring Version ^1.1 | — | — |
symfony/deprecation-contracts Version ^2.5|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant