{"id":"CVE-2026-45077","aliases":["GHSA-m7v2-7gxm-vc2v"],"url":"https://o3.security/vulnerability/CVE-2026-45077","summary":"Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener","details":"### Description\n\n`Symfony\\Bridge\\Monolog\\Command\\ServerLogCommand` (the `server:log` console command) is a development-time helper that opens a TCP listener and displays log records pushed to it by the application's logging pipeline. Two unsafe defaults combine into a remotely reachable PHP object-deserialization sink:\n\n1. The listener binds to `0.0.0.0:9911` by default; it accepts connections on every interface, not only loopback.\n2. Each received frame is processed as `unserialize(base64_decode($message))` without an `allowed_classes` allowlist, without authentication, and without any integrity check. The decoded value is then passed to `displayLog(..., array $record)` which assumes (without validating) that the result is an array.\n\nAny host that can reach TCP port 9911 on a machine running `server:log` can therefore submit attacker-chosen serialized PHP payloads. The minimum impact is an unauthenticated denial of service (sending a non-array, e.g. `serialize(new stdClass())`, crashes the listener with a type error). Object injection with magic-method side effects (`__wakeup()` / `__destruct()` / etc.) is reachable before the array type-check fires; full remote code execution is environment-dependent and contingent on usable gadget chains in the autoload set of the target process.\n\n### Resolution\n\nThe `server:log` command no longer binds to all interfaces by default: the default `--host` is now `127.0.0.1:9911`, requiring explicit opt-in to accept off-host traffic. Message decoding is gated by an `unserialize()` allowlist restricted to the `Symfony\\Component\\VarDumper\\Caster\\*` and `Symfony\\Component\\VarDumper\\Cloner\\*` classes that legitimately appear inside dumped log records; any other class is rejected and the record discarded.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/0891b2f293896c488e26943dc034334364b77fc4) for branch 5.4.\n\n### Credits\n\nSymfony would like to thank Toàn Thắng and Sam Sanoop for reporting the issue and Nicolas Grekas for fixing it.","published":"2026-07-14T17:46:33.837Z","modified":"2026-08-12T03:51:37.691888665Z","cvss":null,"epss":{"score":0.00447,"percentile":0.3723,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"symfony/monolog-bridge","fixedVersion":"5.4.52"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"5.4.52"},{"ecosystem":"Packagist","name":"symfony/monolog-bridge","fixedVersion":"6.4.40"},{"ecosystem":"Packagist","name":"symfony/monolog-bridge","fixedVersion":"7.4.12"},{"ecosystem":"Packagist","name":"symfony/monolog-bridge","fixedVersion":"8.0.12"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"6.4.40"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"7.4.12"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"8.0.12"}],"fix":{"url":"https://github.com/symfony/symfony/commit/0891b2f293896c488e26943dc034334364b77fc4","label":"symfony/symfony@0891b2f"},"references":[{"type":"WEB","url":"https://github.com/symfony/symfony/releases/tag/v5.4.52"},{"type":"WEB","url":"https://github.com/symfony/symfony/releases/tag/v6.4.40"},{"type":"WEB","url":"https://github.com/symfony/symfony/releases/tag/v7.4.12"},{"type":"WEB","url":"https://github.com/symfony/symfony/releases/tag/v8.0.12"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45077.json"},{"type":"ADVISORY","url":"https://github.com/symfony/symfony/security/advisories/GHSA-m7v2-7gxm-vc2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45077"},{"type":"FIX","url":"https://github.com/symfony/symfony/commit/0891b2f293896c488e26943dc034334364b77fc4"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/monolog-bridge/CVE-2026-45077.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2026-45077.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/symfony"},{"type":"WEB","url":"https://symfony.com/cve-2026-45077"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:37.691888665Z"}}