{"id":"CVE-2026-54164","aliases":["GHSA-9rjg-x2p2-h68h"],"url":"https://o3.security/vulnerability/CVE-2026-54164","summary":"API Platform Core: Missing IRI type check enables resource type confusion","details":"## Summary\n\nThe API Platform serializer's `AbstractItemNormalizer` does not validate the resource type returned when resolving relation IRIs, allowing type confusion where a resource of an unintended type can be silently assigned to a relation property.\n\n## Impact\n\nAn attacker who can submit write requests (POST/PUT/PATCH) to an API Platform endpoint with writable relations can supply a relation IRI pointing to a resource of a different type than the relation's declared class. Because `getResourceFromIri()` does not pass an `$operation` to `IriConverter::getResourceFromIri()`, the `is_a` type guard at `IriConverter.php:86` is skipped. For untyped relation properties (legacy `@var`-only style), the wrong-typed object is silently assigned, corrupting invariants and potentially feeding downstream logic that assumes the declared type (CWE-843). For typed properties (modern PHP 8.x), the substitution is blocked by Symfony's PropertyAccessor with an `InvalidTypeException`.\n\n## Affected versions\n\n- `api-platform/core` `< 4.1.30`\n- `api-platform/core` `>= 4.2.0, < 4.2.26`\n- `api-platform/core` `>= 4.3.0, < 4.3.12`\n\nOlder major series (`2.x`, `3.x`) ship the same vulnerable code path and are end-of-life; no fix is planned.\n\n## Patched versions\n\n- `4.1.30`\n- `4.2.26`\n- `4.3.12`\n\n## Fix\n\nAn `is_a` guard is added inside `AbstractItemNormalizer::getResourceFromIri()` (and the equivalent inline call sites on 4.1) so that a mismatched IRI throws `InvalidArgumentException`, mirroring the operation-aware check the `IriConverter` already performs when an operation is supplied. This forces a `400 Bad Request` response for cross-type IRIs instead of a silent assignment.\n\n## Workarounds\n\nDeclare a PHP type on every writable relation property (e.g. `public ?Foo $relation = null;` instead of `@var Foo $relation`). Symfony's `PropertyAccessor` will then reject a mismatched object with `InvalidTypeException`. This does not cover collections of mixed-type interfaces; upgrading to a patched version is the only complete fix.\n\n## Proof of concept\n\nA functional test posts a `Bar` IRI to a `Foo`-declared relation on an untyped property. Without the fix the server responds with `HTTP 201` and the Bar IRI appears in the response payload. With the fix the server responds with `HTTP 400` (`Invalid IRI \"/bars/1\"`).\n\nFull PoC: `tests/Functional/Security/TypeConfusionRelationIriTest.php` in the patched branches.\n\n## References\n\n- `src/Serializer/AbstractItemNormalizer.php` — vulnerable relation IRI load\n- `src/Symfony/Routing/IriConverter.php` — conditional `is_a` guard (operation-aware path)\n\n## Credit\n\nReported by @alexandre-daubois.","published":"2026-07-01T19:14:28.770Z","modified":"2026-08-12T03:51:47.639093426Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"api-platform/core","fixedVersion":"4.1.30"},{"ecosystem":"Packagist","name":"api-platform/core","fixedVersion":"4.2.26"},{"ecosystem":"Packagist","name":"api-platform/core","fixedVersion":"4.3.12"}],"fix":{"url":"https://github.com/api-platform/core/commit/6bcbeb2dbee53db5bb9b4b8e343bffdf7732de1e","label":"api-platform/core@6bcbeb2"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54164.json"},{"type":"ADVISORY","url":"https://github.com/api-platform/core/security/advisories/GHSA-9rjg-x2p2-h68h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54164"},{"type":"WEB","url":"https://github.com/api-platform/core/commit/6bcbeb2dbee53db5bb9b4b8e343bffdf7732de1e"},{"type":"PACKAGE","url":"https://github.com/api-platform/core"},{"type":"WEB","url":"https://github.com/api-platform/core/releases/tag/v4.1.30"},{"type":"WEB","url":"https://github.com/api-platform/core/releases/tag/v4.2.26"},{"type":"WEB","url":"https://github.com/api-platform/core/releases/tag/v4.3.12"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.639093426Z"}}