symfony/polyfill
Packagist2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting symfony/polyfillpage 1 of 1
- CVE-2013-5958NONECVSS 0.0EG 0.0✓ Fixed in 1.10.02014-12-27
vulnerable: v1.0.0 ... v1.9.0 (13 versions)
The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive ha…
- CVE-2026-46644MEDIUMCVSS 6.9EG 6.9✓ Fixed in 1.38.12026-05-28
vulnerable: v1.17.1 ... v1.38.0 (24 versions)
Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code p…
Check whether symfony/polyfill is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for symfony/polyfill CVEs against the assets you own.
Start Free Scan →