CVE-2026-50157: Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter
Applications built with the Auth0 Symphony SDK, using the Authorizer security authenticator to protect HTTP routes may accept OAuth 2.0 bearer access tokens provided through a URL query parameter, in addition to the standard Authorization header, which may increase the risk of access token exposure and replay against protected API endpoints.
References
- github.com/advisories/GHSA-ffq7-hh2j-r24p
- github.com/auth0/symfony/commit/172d1d3e0b9d1e93610d786118389a811179bc8a
- github.com/auth0/symfony/commit/bd1851b14ae15e99cbe87c96496cf25da025288a
- github.com/auth0/symfony/releases/tag/5.9.0
- github.com/auth0/symfony/security/advisories/GHSA-ffq7-hh2j-r24p
- nvd.nist.gov/vuln/detail/CVE-2026-50157
Code Behaviors & Features
Detect and mitigate CVE-2026-50157 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →