Insufficient verification of data authenticity in Symfony - CVE-2026-45069
Published: May 21, 2026
Symfony
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass JWT claim validation.
The vulnerability exists due to insufficient verification of data authenticity in OidcTokenHandler::verifyClaims() when processing a validly signed bearer JWT missing required claims. A remote attacker can supply a validly signed JWT that omits the aud, iss, and exp claims to bypass JWT claim validation.