{"id":"CVE-2026-49212","aliases":["GHSA-34w5-c283-j9fg"],"url":"https://o3.security/vulnerability/CVE-2026-49212","summary":"Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot binding","details":"Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\\UX\\LiveComponent\\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the slot identifier (props vs propsFromParent), or request context, allowing a signed blob minted for one component or slot to be replayed in another and set a read-only prop on a target component. This issue is fixed in versions 2.36.0 and 3.1.0.","published":"2026-07-17T16:03:27.784Z","modified":"2026-08-12T03:51:43.651196224Z","cvss":null,"epss":{"score":0.00242,"percentile":0.1516,"asOf":"2026-09-01"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"symfony/ux-live-component","fixedVersion":"2.36.0"},{"ecosystem":"Packagist","name":"symfony/ux-live-component","fixedVersion":"3.1.0"}],"fix":{"url":"https://github.com/symfony/ux/commit/a224b5af3e2e33ee14ac71356ae0e0877900a81c","label":"symfony/ux@a224b5a"},"references":[{"type":"WEB","url":"https://github.com/symfony/ux/releases/tag/v2.36.0"},{"type":"WEB","url":"https://github.com/symfony/ux/releases/tag/v3.1.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49212.json"},{"type":"ADVISORY","url":"https://github.com/symfony/ux/security/advisories/GHSA-34w5-c283-j9fg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49212"},{"type":"FIX","url":"https://github.com/symfony/ux/commit/a224b5af3e2e33ee14ac71356ae0e0877900a81c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.651196224Z"}}