Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. symfony/lox24-notifier
  4. ›
  5. CVE-2026-45754

CVE-2026-45754: Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection

May 28, 2026

The Mailjet mailer bridge and the LOX24 SMS notifier bridge both ship webhook request parsers used to authenticate and decode the event callbacks each provider POSTs to an application’s webhook endpoint. Their doParse(Request $request, #[\SensitiveParameter] string $secret) methods receive the configured webhook secret but never read it; they convert and return the payload unconditionally.

As a result, an application that wires up either webhook endpoint accepts any POST to that URL, even when a webhook secret is configured (the recommended setup). An attacker who knows the endpoint exists can submit forged event payloads, fake bounce / blocked / spam / open / click / delivery events, leading to suppression-list corruption, delivery-metrics fraud, etc.

References

  • github.com/FriendsOfPHP/security-advisories/blob/master/symfony/lox24-notifier/CVE-2026-45754.yaml
  • github.com/FriendsOfPHP/security-advisories/blob/master/symfony/mailjet-mailer/CVE-2026-45754.yaml
  • github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2026-45754.yaml
  • github.com/advisories/GHSA-64hg-93w9-fc35
  • github.com/symfony/symfony/commit/4aaa45dd054f73445f1ab254968b7e60b546cc77
  • github.com/symfony/symfony/security/advisories/GHSA-64hg-93w9-fc35
  • nvd.nist.gov/vuln/detail/CVE-2026-45754
  • symfony.com/cve-2026-45754

Code Behaviors & Features

Detect and mitigate CVE-2026-45754 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 7.1.0 before 7.4.12, all versions starting from 8.0.0 before 8.0.12

Fixed versions

  • 7.4.12
  • 8.0.12

Solution

Upgrade to versions 7.4.12, 8.0.12 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-287: Improper Authentication
  • CWE-306: Missing Authentication for Critical Function

Source file

packagist/symfony/lox24-notifier/CVE-2026-45754.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 29 May 2026 12:17:45 +0000.