An open index of dependabot pull requests across open source projects.

symfony/http-foundation

Ecosystem:
packagist
Package URL:
pkg:composer/symfony/http-foundation
Total PRs:
402 Dependabot PRs
Latest PR:
about 4 hours ago
Unique Repositories:
286 repositories
Unique Repos (30 days):
86 repositories
Security Advisories
Symfony has a security issue when parsing the Authorization header
GHSA-h7v2-2qwg-h829 CVE-2014-6061 MODERATE published over 1 year ago • updated 11 days ago
All 2.0.X, 2.1.X, 2.2.X, 2.3.X, 2.4.X, and 2.5.X versions of the Symfony HttpFoundation component are affected by this security issue. This issue ...
Prevent cache poisoning via a Response Content-Type header in Symfony
GHSA-mcx4-f5f5-4859 CVE-2020-5255 LOW published over 5 years ago • updated about 17 hours ago
Description ----------- When a `Response` does not contain a `Content-Type` header, Symfony falls back to the format defined in the `Accept` heade...
Invalid HTTP method overrides allow possible XSS or other attacks in Symfony
GHSA-x92h-wmg2-6hp7 CVE-2019-10913 CRITICAL published almost 6 years ago • updated about 13 hours ago
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or usin...
Argument injection in a MimeTypeGuesser in Symfony
GHSA-xhh6-956q-4q69 CVE-2019-18888 HIGH published almost 6 years ago • updated 3 days ago
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application pas...
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
GHSA-3rg7-wf37-54rm CVE-2025-64500 HIGH published 13 days ago • updated 3 days ago
### Description The `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't ...
Recent PRs
Package Details
Name: symfony/http-foundation
Ecosystem: packagist
PURL Type: composer
Package URL: pkg:composer/symfony/http-foundation
JSON API: View JSON
Security Advisories

11

Active advisories
CRITICAL 1
HIGH 3
MODERATE 5
LOW 2
View All composer Advisories
Package Information
Description:

Defines an object-oriented layer for the HTTP specification

Repository: https://github.com/symfony/http-foundation
Homepage: https://symfony.com
Latest Release: v7.3.0
7 months ago
Dependent Repos: 533,200
Dependent Packages: 4,613
Downloads: 747,469,299
Ranking: Top 0.0056% by dependent repos Top 0.0068% by downloads Top 0.0081% by dependent pkgs
PR Status
Open 175 (43.9%)
Merged 63 (15.8%)
Closed 138 (34.6%)
PR Types
Minor 134 (33.6%)
Major 9 (2.3%)
Patch 231 (57.9%)