CVE-2025-64500

Published Nov 12, 2025

Last updated 3 months ago

CVSS high 7.3
Symfony
HTTP

Overview

Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.
Source
security-advisories@github.com
NVD status
Analyzed
Products
httpfoundation, symfony

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.3
Impact score
3.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-647

Social media

Hype score
Not currently trending
  1. ๐Ÿšจ CVE-2025-64500 - high ๐Ÿšจ Symfony HttpFoundation - Access Control Bypass via PATH_INFO > Symfony HttpFoundation component >= 2.0.0 and prior to versions 5.4.50, 6.4.29, and 7... ๐Ÿ‘พ https://t.co/mTCfBsqYa0 @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    3 Apr 2026

    220 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. #VulnerabilityReport #AuthorizationBypass Symfony Patches PATH_INFO Parsing Flaw Leading to Authorization Bypass (CVE-2025-64500) https://t.co/Dw2h7h39wi

    @Komodosec

    22 Dec 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Une faille dans Symfony permet de contourner les rรจgles d'accรจs - CVE-2025-64500 https://t.co/7zY5T7ugQn

    @ytroncal

    1 Dec 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-64500: Authorization Bypass in Symfony, 7.3 ratingโ—๏ธ The vulnerability allows attackers to bypass certain access restrictions based on the leading "/" character. Search at https://t.co/hv7QKSqxTR: ๐Ÿ‘‰ Link: https://t.co/XNZRrw80AE https://t.co/VewdOZPXoa

    @Netlas_io

    17 Nov 2025

    1176 Impressions

    3 Retweets

    11 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  5. ๐Ÿ” ๐’๐ฒ๐ฆ๐Ÿ๐จ๐ง๐ฒ ๐๐š๐ญ๐œ๐ก๐ž๐ฌ ๐๐€๐“๐‡_๐ˆ๐๐…๐Ž ๐๐š๐ซ๐ฌ๐ข๐ง๐  ๐…๐ฅ๐š๐ฐ ๐‹๐ž๐š๐๐ข๐ง๐  ๐ญ๐จ ๐€๐ฎ๐ญ๐ก๐จ๐ซ๐ข๐ณ๐š๐ญ๐ข๐จ๐ง ๐๐ฒ๐ฉ๐š๐ฌ๐ฌ (๐‚๐•๐„-๐Ÿ

    @PurpleOps_io

    15 Nov 2025

    28 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  6. โš ๏ธโš ๏ธ CVE-2025-64500: In Symfony HTTP Foundation vulnerable versions (< 5.4.50, < 6.4.29, < 7.3.7), incorrect parsing of PATH_INFO can lead to a limited authorization bypass ๐ŸŽฏ23.8k+ Results are found on the https://t.co/pb16tGYaKe nearly year. ๐Ÿ”—FOFA Link: ht

    @fofabot

    14 Nov 2025

    939 Impressions

    3 Retweets

    12 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  7. ๐Ÿšจ๐ŸšจCVE-2025-64500: Symfony's PATH_INFO parser glitch lets URLs slip without leading /โ€”bypassing access controls that assume it. Search by vul.cve Filter๐Ÿ‘‰vul.cve="CVE-2025-64500" ZoomEye Dork๐Ÿ‘‰app="Symfony" Found 32K+ instances on ZoomEye. ZoomEye Link: https://t.co/b

    @zoomeye_team

    13 Nov 2025

    2491 Impressions

    7 Retweets

    31 Likes

    11 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2025-64500 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer โ€ฆ https://t.co/mCK0SZUQUe

    @CVEnew

    13 Nov 2025

    190 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. ๐Ÿ” CVE-2025-64500: Incorrect parsing of PATH_INFO can lead to limited authorization bypass โžก๏ธ https://t.co/hS4YbdNBMV

    @symfony

    12 Nov 2025

    4589 Impressions

    8 Retweets

    29 Likes

    6 Bookmarks

    2 Replies

    1 Quote

  10. ๐Ÿ” CVE-2025-64500: Command execution hijack on Windows with Process class โžก๏ธ https://t.co/nvvaHvsaqp

    @symfony

    12 Nov 2025

    2098 Impressions

    3 Retweets

    12 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

Configurations