Tuesday, September 22, 2026
EN

Subscribe in your feed reader — pick your desks:

https://php-net.pro/en/news/feed.atom

php-net.pro · the dev news broadsheet

The Dev Dispatch

PHP · Security

Symfony JsonPath regex denial-of-service flaw

CVE-2026-45756 describes a denial-of-service vulnerability in Symfony JsonPath filters that stems from attacker-supplied regex patterns. Malicious input can trigger exponential backtracking in regex matching, starving CPU and halting service. The CVE record lacks version boundaries, patch status, and proof-of-concept data.

Read the original source ↗

Rate this article: 0

Comments

No comments yet — be the first.