Symfony JsonPath regex denial-of-service flaw
CVE-2026-45756 describes a denial-of-service vulnerability in Symfony JsonPath filters that stems from attacker-supplied regex patterns. Malicious input can trigger exponential backtracking in regex matching, starving CPU and halting service. The CVE record lacks version boundaries, patch status, and proof-of-concept data.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.