Insufficient verification of data authenticity in Symfony - CVE-2026-45069
Published: May 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass JWT claim validation.
The vulnerability exists due to insufficient verification of data authenticity in OidcTokenHandler::verifyClaims() when processing a validly signed bearer JWT missing required claims. A remote attacker can supply a validly signed JWT that omits the aud, iss, and exp claims to bypass JWT claim validation.
Affected software
Debian Linux
symfony (Debian package)
How to mitigate CVE-2026-45069
symfony (Debian package) - update to 6.4.41+dfsg-0+deb13u1