MEDIUM
Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Published Jul 14, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.45%
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not verify them, allowing unauthenticated POST requests to inject forged Mailjet and LOX24 event payloads. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
Affected products
-
- Version >= 7.1.0-BETA1, < 7.4.12StatusaffectedConstraints-
- Version >= 8.0.0-BETA1, < 8.0.12StatusaffectedConstraints-
- Version
-
- Version >= 6.4.0, < 6.4.40StatusaffectedConstraints-
- Version >= 7.0.0-BETA1, < 7.4.12StatusaffectedConstraints-
- Version >= 8.0.0-BETA1, < 8.0.12StatusaffectedConstraints-
- Version
-
- Version >= 6.4.0, < 6.4.40StatusaffectedConstraints-
- Version >= 7.0.0-BETA1, < 7.4.12StatusaffectedConstraints-
- Version >= 8.0.0-BETA1, < 8.0.12StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Symfony | Lox24-Notifier | n/a |
| ||||||||||||
| Symfony | Mailjet-Mailer | n/a |
| ||||||||||||
| Symfony | Symfony | n/a |
|
OR
- ≥ 6.4.0 · < 6.4.40
- ≥ 7.0.0 · < 7.4.12
- ≥ 8.0.0 · < 8.0.12
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44360 Advisory
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/lox24-notifier/CVE-2026-45754.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/mailjet-mailer/CVE-2026-45754.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2026-45754.yaml
- https://github.com/advisories/GHSA-64hg-93w9-fc35 Advisory
- https://github.com/symfony/symfony/commit/3e52bf5ab733ee32e35eeeeb2631d859c941838e x_refsource_MISCPatch
- https://github.com/symfony/symfony/commit/4aaa45dd054f73445f1ab254968b7e60b546cc77 x_refsource_MISCPatch
- https://github.com/symfony/symfony/releases/tag/v6.4.40 x_refsource_MISCRelease Notes
- https://github.com/symfony/symfony/releases/tag/v7.4.12 x_refsource_MISCRelease Notes
- https://github.com/symfony/symfony/releases/tag/v8.0.12 x_refsource_MISCRelease Notes
- https://github.com/symfony/symfony/security/advisories/GHSA-64hg-93w9-fc35 x_refsource_CONFIRMPatchVendor Advisory
- https://symfony.com/cve-2026-45754
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 14, 2026
Updated Jul 21, 2026
Reserved May 13, 2026
Link CVE-2026-45754
CISA Vulnrichment
Updated Jul 21, 2026
ENISA EUVD
EUVD-2026-44360 GHSA-64HG-93W9-FC35 Assigner GitHub_M
Published Jul 14, 2026
Updated Jul 21, 2026
Exploited since n/a
Link EUVD-2026-44360