GHSA-ffq7-hh2j-r24p

Suggest an improvement
Source
https://github.com/advisories/GHSA-ffq7-hh2j-r24p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-ffq7-hh2j-r24p/GHSA-ffq7-hh2j-r24p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-ffq7-hh2j-r24p
Aliases
Published
2026-07-14T19:31:23Z
Modified
2026-07-28T05:30:29Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter
Details

Description

Applications built with the Auth0 Symphony SDK, using the Authorizer security authenticator to protect HTTP routes may accept OAuth 2.0 bearer access tokens provided through a URL query parameter, in addition to the standard Authorization header, which may increase the risk of access token exposure and replay against protected API endpoints.

Resolution

Upgrade auth0/symfony to version 5.9.0 or greater.

Acknowledgement

Okta would like to thank Alex Yeara for their discovery.

Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-598"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-14T19:31:23Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

Packagist / auth0/symfony

Package

Name
auth0/symfony
Purl
pkg:composer/auth0/symfony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0-BETA0
Fixed
5.9.0

Affected versions

5.*
5.0.0-BETA0
5.0.0-BETA1
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.6.0
5.7.0
5.8.0

Database specific

last_known_affected_version_range
"<= 5.8.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-ffq7-hh2j-r24p/GHSA-ffq7-hh2j-r24p.json"