Register for the AI for Security Summit: Join Figma, Perplexity & Wiz
Vulnerability DatabaseGHSA-mmcv-fvq8-r9x3

GHSA-mmcv-fvq8-r9x3
PHP vulnerability analysis and mitigation

Overview

The XMLEncoder component of Symfony 2.0.x contains a critical security vulnerability (GHSA-mmcv-fvq8-r9x3) that fails to disable external entities when parsing XML. This vulnerability affects Symfony versions 2.0.0 to 2.0.11 and was discovered and reported by Sense of Security on February 24, 2012. The issue impacts the Serializer component, which is used for deserializing objects or as part of client/server API functionality (Symfony Blog, GitHub Advisory).

Technical details

The vulnerability has been assigned a Critical severity rating with a CVSS score of 9.8. The attack vector is network-based with low attack complexity, requiring no privileges or user interaction. The vulnerability allows for unauthorized access with high impact on confidentiality, integrity, and availability. The issue specifically relates to the XMLEncoder component's failure to properly handle external entities during XML parsing, which could lead to security breaches (GitHub Advisory).

Impact

When exploited, this vulnerability allows attackers to include arbitrary files from the file system through external entities. For example, attackers could potentially access sensitive system files such as /etc/passwd in base64 encoded form through XML deserialization (Symfony Blog).

Exploitability

The vulnerability is easily exploitable through XML deserialization. A proof of concept exploit was provided demonstrating how an attacker could use the Serializer component with XMLEncoder to access system files. The exploit requires minimal setup and can be executed through standard XML parsing operations (Symfony Blog).

Mitigation and workarounds

The vulnerability was patched in Symfony version 2.0.11. Users are strongly advised to upgrade to this version or apply the appropriate security patch. The fix, implemented by Jordi Boggiano, involves properly disabling external entity loading during XML parsing. For users unable to upgrade immediately, the patch can be applied directly to the affected components (Symfony Blog, GitHub Commit).

Community reactions

The Symfony team demonstrated rapid response to the security issue, releasing the patch on the same day it was reported. The community praised the quick response time and transparency in handling the security vulnerability. The fix was well-received by the developer community, with several community members acknowledging the swift action taken to address the security concern (Symfony Blog).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71537MEDIUM6.5
  • PHP logoPHP
  • paymenter/paymenter
NoYesSep 18, 2026
CVE-2026-77616MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77610MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77609MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77608MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management