Improper Verification of Cryptographic Signature in Symfony - CVE-2026-47212
Published: May 21, 2026
Symfony
Detailed vulnerability description
The vulnerability allows a remote attacker to inject forged webhook events.
The vulnerability exists due to improper verification of cryptographic signature in the TwilioRequestParser webhook request parser when handling webhook POST requests. A remote attacker can send a specially crafted request to inject forged webhook events.
This affects applications that expose the Twilio webhook endpoint and have a signing secret configured, because the parser ignores the X-Twilio-Signature header and accepts arbitrary status payloads.