The password reset tokenand API key generation uses a weak cryptographical hash algorithm.
Fixed in 2.6.23 and 3.0.6 version.
Patch the related User.php and ResettingController.php file in the SecurityBundle.
{
"github_reviewed_at": "2026-05-18T17:27:22Z",
"nvd_published_at": null,
"cwe_ids": [
"CWE-327"
],
"severity": "MODERATE",
"github_reviewed": true
}