Symfony JsonPath regex denial-of-service flaw
CVE-2026-45756 describes a denial-of-service vulnerability in Symfony JsonPath filters that stems from attacker-supplied regex patterns.
R/PHP (TOP), September 22, 2026
curated by Heiko
Malicious input can trigger exponential backtracking in regex matching, starving CPU and halting service. The CVE record lacks version boundaries, patch status, and proof-of-concept data.
Readers’ Forum
No contributions yet — open the debate.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.