Provides a tight integration of the Security component into the Symfony full-stack framework
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11003 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. symfony/security-bundle is vulnerable to Improper Authentication in versions 6.4.0 - 6.4.39, 7.4.0 - 7.4.12 and 8.0.0 - 8.0.12. | 6.4.0 - 6.4.397.4.0 - 7.4.128.0.0 - 8.0.12 | |
CVE-2024-50341 symfony/security-bundle is vulnerable to Improper Authentication in versions 6.2.0 - 6.4.10, 7.0.0 - 7.0.10 and 7.1.0 - 7.1.3. | 6.2.0 - 6.4.107.0.0 - 7.0.107.1.0 - 7.1.3 | |
CVE-2022-24895 symfony/security-bundle is vulnerable to Session Fixation in versions 2.0.0 - 4.4.50, 5.0.0 - 5.4.20, 6.0.0 - 6.0.20, 6.1.0 - 6.1.12 and 6.2.0 - 6.2.6. | 2.0.0 - 4.4.505.0.0 - 5.4.206.0.0 - 6.0.20 +2 more | |
CVE-2021-41268 symfony/security-bundle is vulnerable to Session Fixation in versions 5.3.0 - 5.3.12. | 5.3.0 - 5.3.12 |
| Dependency | Last Release | Score |
|---|---|---|
symfony/clock Version ^7.4|^8.0 | — | — |
symfony/config Version ^7.4|^8.0 | — | — |
symfony/http-kernel Version ^7.4|^8.0 | — | — |
symfony/security-core Version ^7.4|^8.0 | — | — |
symfony/security-csrf Version ^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant