漏洞描述
Symfony HttpFoundation component >= 2.0.0 and prior to versions 5.4.50, 6.4.29, and 7.3.7 contains an access control bypass vulnerability. The Request class improperly interprets some PATH_INFO values, producing URL paths without a leading `/`. This allows bypassing access control rules that are built with the `/-prefix` assumption.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/symfony/symfony/security/advisories/GHSA-3rg7-wf37-54rm↗symfony.comhttps://symfony.com/blog/cve-2025-64500-incorrect-parsing-of-path-info-can-lead-to-limited-authorization-bypass↗github.comhttps://github.com/symfony/symfony/commit/9962b91b12bb791322fa73836b350836b6db7cac↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-64500↗