CVE-2026-45077 — monolog-bridge
Fix: symfony/symfony@0891b2fCVE-2026-45077 is a Deserialization of Untrusted Data vulnerability in symfony/monolog-bridge. A fix is available for symfony/monolog-bridge — see the affected versions and patch details below.
Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
Exploitation Status
No confirmed exploitation observed yet
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-45077.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
symfony/monolog-bridge🐘symfony/symfony🐘symfony/monolog-bridge🐘symfony/monolog-bridge🐘symfony/monolog-bridge🐘symfony/symfony🐘symfony/symfony🐘symfony/symfonyReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.
Description
Description
Symfony\Bridge\Monolog\Command\ServerLogCommand (the server:log console command) is a development-time helper that opens a TCP listener and displays log records pushed to it by the application's logging pipeline. Two unsafe defaults combine into a remotely reachable PHP object-deserialization sink:
- The listener binds to
0.0.0.0:9911by default; it accepts connections on every interface, not only loopback. - Each received frame is processed as
unserialize(base64_decode($message))without anallowed_classesallowlist, without authentication, and without any integrity check. The decoded value is then passed todisplayLog(..., array $record)which assumes (without validating) that the result is an array.
Any host that can reach TCP port 9911 on a machine running server:log can therefore submit attacker-chosen serialized PHP payloads. The minimum impact is an unauthenticated denial of service (sending a non-array, e.g. serialize(new stdClass()), crashes the listener with a type error). Object injection with magic-method side effects (__wakeup() / __destruct() / etc.) is reachable before the array type-check fires; full remote code execution is environment-dependent and contingent on usable gadget chains in the autoload set of the target process.
Resolution
The server:log command no longer binds to all interfaces by default: the default --host is now 127.0.0.1:9911, requiring explicit opt-in to accept off-host traffic. Message decoding is gated by an unserialize() allowlist restricted to the Symfony\Component\VarDumper\Caster\* and Symfony\Component\VarDumper\Cloner\* classes that legitimately appear inside dumped log records; any other class is rejected and the record discarded.
The patch for this issue is available here for branch 5.4.
Credits
Symfony would like to thank Toàn Thắng and Sam Sanoop for reporting the issue and Nicolas Grekas for fixing it.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐘Packagist | symfony/monolog-bridge | all versions | 5.4.52composer require symfony/monolog-bridge:^5.4.52 |
| 🐘Packagist | symfony/symfony | all versions | 5.4.52composer require symfony/symfony:^5.4.52 |
| 🐘Packagist | symfony/monolog-bridge | ≥ 6.0.0&&< 6.4.40 | 6.4.40composer require symfony/monolog-bridge:^6.4.40 |
| 🐘Packagist | symfony/monolog-bridge | ≥ 7.0.0&&< 7.4.12 | 7.4.12composer require symfony/monolog-bridge:^7.4.12 |
| 🐘Packagist | symfony/monolog-bridge | ≥ 8.0.0&&< 8.0.12 | 8.0.12composer require symfony/monolog-bridge:^8.0.12 |
| 🐘Packagist | symfony/symfony | ≥ 6.0.0&&< 6.4.40 | 6.4.40composer require symfony/symfony:^6.4.40 |
Affected Products
symfonysensiolabsDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for symfony/monolog-bridge, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update symfony/monolog-bridge to 5.4.52 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-45077 is resolved across your whole dependency graph.
Workarounds
Do not deserialise data from untrusted sources: where the format allows it, restrict deserialisation to an explicit allowlist of expected types, and prefer a data-only format (JSON, Protobuf) over one that can reconstruct arbitrary objects until you can upgrade.
Frequently Asked Questions
Is CVE-2026-45077 in your dependencies?
Find it across Packagist, including transitive dependencies.