Improper Verification of Cryptographic Signature in Symfony - CVE-2026-45755
Published: May 21, 2026
Symfony
Detailed vulnerability description
The vulnerability allows a remote attacker to inject forged webhook events.
The vulnerability exists due to improper verification of cryptographic signature in MailtrapRequestParser::doParse() when handling webhook POST requests. A remote attacker can send a specially crafted request to inject forged webhook events.
An application that exposes the webhook endpoint and has a signing secret configured will still accept unsigned or forged event payloads.