Back

MEDIUM

Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection

Published Jul 14, 2026

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not verify them, allowing unauthenticated POST requests to inject forged Mailjet and LOX24 event payloads. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

Affected products

Remediation

No remediation recorded yet.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 14, 2026
Updated Jul 21, 2026
Reserved May 13, 2026
CISA Vulnrichment
Updated Jul 21, 2026
NVD
Status Analyzed
Modified Jul 21, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Jul 14, 2026
Updated Jul 21, 2026
Exploited since n/a
EUVD-2026-44360 GHSA-64HG-93W9-FC35