PT-2026-42702 · Unknown · Knpsnappybundle

Published

2026-05-21

·

Updated

2026-05-21

·

CVE-2026-46683

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions KnpSnappyBundle (affected versions not specified)
Description An issue exists that allows Server-Side Request Forgery (SSRF) and local file read. This occurs when applications allow user-supplied input to be passed directly to the Snappy library, specifically through the xsl-style-sheet parameter. The impact is most severe when the PHP daemon runs with root permissions and the application is running outside a container or has access to sensitive files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Ensure that user input is not passed directly to the Snappy library. Instead, implement a whitelist of allowed stylesheets and select the appropriate one based on user input. Restrict the use of the xsl-style-sheet parameter to prevent unauthorized file access or remote requests.

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-46683
GHSA-C5FP-P67M-GQ56

Affected Products

Knpsnappybundle