{"id":"CVE-2016-4423","aliases":["GHSA-whgv-8cg3-7hcm"],"url":"https://o3.security/vulnerability/CVE-2016-4423","summary":"Symphony Denial of Service Via Overlong Usernames","details":"The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.","published":"2016-06-01T22:59:02.457Z","modified":"2026-08-07T11:47:45.181406966Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.01862,"percentile":0.78231,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"2.3.41"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"2.7.13"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"2.8.6"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"3.0.6"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"2.3.41"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"2.7.13"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"2.8.6"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"3.0.6"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"2.3.41"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"2.7.13"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"2.8.6"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"3.0.6"}],"fix":{"url":"https://github.com/symfony/symfony/pull/18733","label":"symfony/symfony#18733"},"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3588"},{"type":"ADVISORY","url":"https://symfony.com/blog/cve-2016-4423-large-username-storage-in-session"},{"type":"FIX","url":"https://github.com/symfony/symfony/pull/18733"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:47:45.181406966Z"}}