๐Ÿ” CVE Alert

CVE-2026-50157

MEDIUM 6.5

Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as the Authorization header for protected HTTP routes. Query-string tokens can be recorded in server logs, browser history, or referrer data and then replayed against protected API endpoints. This issue is fixed in version 5.9.0.

CWE CWE-598
Vendor auth0
Product symfony
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for auth0 symfony

Be the first to know when new medium vulnerabilities affecting auth0 symfony are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

auth0 / symfony
>= 5.0.0-BETA0, < 5.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/auth0/symfony/security/advisories/GHSA-ffq7-hh2j-r24p github.com: https://github.com/auth0/symfony/commit/bd1851b14ae15e99cbe87c96496cf25da025288a github.com: https://github.com/auth0/symfony/releases/tag/5.9.0