An open index of dependabot pull requests across open source projects.

symfony/http-kernel

Ecosystem:
packagist
Package URL:
pkg:composer/symfony/http-kernel
Total PRs:
280 Dependabot PRs
Latest PR:
17 days ago
Unique Repositories:
166 repositories
Unique Repos (30 days):
16 repositories
Security Advisories
Synfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]
GHSA-6439-2f28-8p8q CVE-2026-45075 MODERATE published 23 days ago • updated 3 days ago
### Description Symfony's `#[IsGranted('...')]`, `#[IsSignatureValid]`, and `#[IsCsrfTokenValid(...)]` attributes allow you to define a `methods: ...
Symfony Http-Kernel has non-constant time comparison in UriSigner
GHSA-q8hg-pf8v-cxrv CVE-2019-18887 HIGH published about 4 years ago • updated about 17 hours ago
When checking the signature of an URI (an ESI fragment URL for instance), the URISigner did not used a constant time string comparison function, re...
Symfony allows direct access of ESI URLs behind a trusted proxy
GHSA-wvjv-p5rr-mmqm CVE-2014-5245 HIGH published about 2 years ago • updated about 6 hours ago
All 2.2.X, 2.3.X, 2.4.X, and 2.5.X versions of the Symfony HttpKernel component are affected by this security issue. Your application is vulnerable...
Symfony Incorrect Access Control
GHSA-qmqw-mpqp-mr54 CVE-2015-4050 MODERATE published about 4 years ago • updated about 4 hours ago
FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7,...
Webcache Poisoning in symfony/http-kernel
GHSA-q3j3-w37x-hq2q CVE-2021-41267 MODERATE published over 4 years ago • updated about 14 hours ago
Description ----------- When a Symfony application is running behind a proxy or a load-balancer, you can tell Symfony to look for the `X-Forwarded...
Recent PRs
Package Details
Name: symfony/http-kernel
Ecosystem: packagist
PURL Type: composer
Package URL: pkg:composer/symfony/http-kernel
JSON API: View JSON
Security Advisories

8

Active advisories
HIGH 3
MODERATE 5
View All composer Advisories
Package Information
Description:

Provides a structured process for converting a Request into a Response

Repository: https://github.com/symfony/http-kernel
Homepage: https://symfony.com
Latest Release: v7.2.6
about 1 year ago
Dependent Repos: 534,064
Dependent Packages: 5,492
Downloads: 696,099,444
Ranking: Top 0.0054% by dependent repos Top 0.0086% by downloads Top 0.0061% by dependent pkgs
PR Status
Open 86 (30.7%)
Merged 44 (15.7%)
Closed 142 (50.7%)
PR Types
Major 8 (2.9%)
Minor 53 (18.9%)
Patch 210 (75.0%)