Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-ffq7-hh2j-r24p | Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter |
Mon, 14 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as the Authorization header for protected HTTP routes. Query-string tokens can be recorded in server logs, browser history, or referrer data and then replayed against protected API endpoints. This issue is fixed in version 5.9.0. | |
| Title | Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK | |
| Weaknesses | CWE-598 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-14T20:06:21.452Z
Reserved: 2026-06-03T20:54:20.432Z
Link: CVE-2026-50157
Updated: 2026-09-14T19:20:55.595Z
Status : Received
Published: 2026-09-14T18:17:49.663
Modified: 2026-09-14T20:16:45.027
Link: CVE-2026-50157
No data.
OpenCVE Enrichment
No data.
Github GHSA