PT-2024-34153 · Symfony+5 · Symfony/Validator+5

Offscriptian

·

Published

2024-08-13

·

Updated

2025-07-01

·

CVE-2024-50343

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: symfony/validator versions 5.4.43, 6.4.11, and 7.1.4
Description: The symfony/validator module in the Symphony PHP framework is vulnerable to a regex bypass issue. It is possible to trick a Validator configured with a regular expression using the $ metacharacters, with an input ending with . This issue can be exploited by providing a specially crafted input. Symfony now uses the D regex modifier to match the entire input.
Recommendations: For versions 5.4.43, 6.4.11, and 7.1.4, upgrade to a newer version that includes the patch for this issue. As a temporary workaround, consider configuring the Validator to use the D regex modifier to match the entire input until a patch is available.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-07864
CVE-2024-50343
DLA-4200-1
DSA-5809-1
GHSA-G3RH-RRHP-JHH9
USN-7272-1

Affected Products

Astra Linux
Debian
Linuxmint
Red Os
Ubuntu
Symfony/Validator