{"id":"CVE-2026-45075","aliases":["GHSA-6439-2f28-8p8q"],"url":"https://o3.security/vulnerability/CVE-2026-45075","summary":"Symfony: HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]","details":"### Description\n\nSymfony's `#[IsGranted('...')]`, `#[IsSignatureValid]`, and `#[IsCsrfTokenValid(...)]` attributes allow you to define a `methods: [...]` argument to only enforce these checks for the listed HTTP methods and skip them otherwise. E.g. an attribute defining `methods: ['GET']` would be ignored for a `HEAD` request.\n\nOn the other hand, Symfony's router (and HTTP semantics generally) serves `HEAD` requests using the `GET` handler. Therefore, a controller protected by e.g. `#[IsGranted('ROLE_ADMIN', methods: ['GET'])]` can be reached via `HEAD` with the authorization check silently skipped.\n\nEven if the `HEAD` request won't get any response content, response headers leak (`Content-Length`, `Location`, custom headers). Also, the controller still executes and any side effects (DB writes, state changes) occur.\n\n### Resolution\n\nWhen adding `GET` in the `methods` option of these attributes, Symfony now also include the `HEAD` method automatically.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/fa8d5c67aa4b22c9656e3fd7d5c3aa59865bf838) for branch 7.4.\n\n### Credits\n\nSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and Alexandre Daubois for fixing it.","published":"2026-07-14T18:40:37.287Z","modified":"2026-08-12T03:51:22.464750315Z","cvss":null,"epss":{"score":0.00429,"percentile":0.36525,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"symfony/http-kernel","fixedVersion":"7.4.12"},{"ecosystem":"Packagist","name":"symfony/http-kernel","fixedVersion":"8.0.12"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"7.4.12"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"8.0.12"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"7.4.12"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"8.0.12"}],"fix":{"url":"https://github.com/symfony/symfony/commit/fa8d5c67aa4b22c9656e3fd7d5c3aa59865bf838","label":"symfony/symfony@fa8d5c6"},"references":[{"type":"WEB","url":"https://github.com/symfony/symfony/releases/tag/v7.4.12"},{"type":"WEB","url":"https://github.com/symfony/symfony/releases/tag/v8.0.12"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45075.json"},{"type":"ADVISORY","url":"https://github.com/symfony/symfony/security/advisories/GHSA-6439-2f28-8p8q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45075"},{"type":"WEB","url":"https://github.com/symfony/symfony/commit/fa8d5c67aa4b22c9656e3fd7d5c3aa59865bf838"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-kernel/CVE-2026-45075.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-http/CVE-2026-45075.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2026-45075.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/symfony"},{"type":"WEB","url":"https://symfony.com/cve-2026-45075"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.464750315Z"}}