symfony/ux-live-component
Packagist6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting symfony/ux-live-componentpage 1 of 1
- CVE-2025-47946MEDIUMCVSS 6.1EG 6.1fixed in 2.25.12025-05-19
vulnerable: v2.0.0 ... v2.9.1 (42 versions)
Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. `only()`, `defa…
- CVE-2026-49208MEDIUMCVSS 5.3EG 5.3fixed in 2.36.0 or 3.1.0, by version range2026-06-19
vulnerable: v3.0.0
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, Symfony\UX\LiveComponent\LiveComponentHydrator::hydrateObjectValue(…
- CVE-2026-49209MEDIUMCVSS 6.5EG 6.5fixed in 2.36.0 or 3.1.0, by version range2026-06-19
vulnerable: v3.0.0
Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-req…
- CVE-2026-49210MEDIUMCVSS 6.1EG 6.1fixed in 2.36.0 or 3.1.0, by version range2026-06-19
vulnerable: v3.0.0
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubs…
- CVE-2026-49212HIGHCVSS 7.5EG 7.5fixed in 2.36.0 or 3.1.0, by version range2026-06-19
vulnerable: v3.0.0
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the s…
- CVE-2026-49215MEDIUMCVSS 5.4EG 5.4fixed in 2.36.0 or 3.1.0, by version range2026-06-19
vulnerable: v3.0.0
Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventListener\LiveComponentSubscriber::isLiveComponentRequest() gates #[LiveAction] invocations on Accept: application/vnd.live-…
Check whether symfony/ux-live-component is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for symfony/ux-live-component CVEs against the assets you own.
Book a Demo →