# Multiple vulnerabilities in Symfony framework versions 5.4–8.0 enable SSRF, XSS, and…

Published: 2026-05-27 · Severity: high
Canonical: https://vorant.io/reports/18dde788-ac7f-4027-b92a-6b80d41e669a/multiple-vulnerabilities-in-symfony-framework-versions-5-4-8-0-enable-ssrf-xss

> Multiple vulnerabilities in Symfony framework versions 5.4–8.0 enable SSRF, XSS, and security policy bypass; patches available from vendor.

The French CERT (CERT-FR) published an advisory disclosing multiple vulnerabilities affecting the Symfony web application framework across versions 5.4.x through 8.0.x. The flaws enable several attack vectors including server-side request forgery (SSRF), cross-site scripting (XSS), and security policy bypass. Six distinct GitHub Security Advisories and CVE identifiers have been assigned to these issues.

Affected versions include Symfony 5.4.x prior to 5.4.53, 6.4.x prior to 6.4.41, 7.0.x prior to 7.4.13, and 8.0.x prior to 8.0.13. The vendor has released patches addressing all identified vulnerabilities. Organizations running Symfony-based applications should prioritize updates to the latest patched releases within their respective version streams.

The advisory references six separate security bulletins published by Symfony on May 27, 2026, each detailing specific vulnerability conditions and remediation guidance. Given Symfony's widespread use in enterprise web applications, these vulnerabilities present significant risk to organisations that have not yet applied the available patches.

## Mentioned in this report

- Vulnerabilities: CVE-2026-48489, CVE-2026-48736, CVE-2026-48747, CVE-2026-48760, CVE-2026-48761, CVE-2026-48784

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0653

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/18dde788-ac7f-4027-b92a-6b80d41e669a/multiple-vulnerabilities-in-symfony-framework-versions-5-4-8-0-enable-ssrf-xss.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
