{"id":"CVE-2026-45755","summary":"Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection","details":"Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configured webhook secret but ignored the X-Mt-Signature HMAC header, allowing unauthenticated POST requests to inject forged Mailtrap delivery, bounce, open, click, or spam events. This issue is fixed in versions 7.4.12 and 8.0.12.","aliases":["GHSA-59f3-vp2f-mp9w"],"modified":"2026-07-17T03:46:45.279587937Z","published":"2026-07-14T18:56:20.615Z","database_specific":{"cwe_ids":["CWE-306","CWE-347"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45755.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/symfony/symfony/releases/tag/v7.4.12"},{"type":"WEB","url":"https://github.com/symfony/symfony/releases/tag/v8.0.12"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45755.json"},{"type":"ADVISORY","url":"https://github.com/symfony/symfony/security/advisories/GHSA-59f3-vp2f-mp9w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45755"},{"type":"FIX","url":"https://github.com/symfony/symfony/commit/4e0467e4e182cf2e704a3d9e1bc1a6be65d52ab8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/symfony/security-http","events":[{"introduced":"0d0ab4d491f22306c893b2d30ce73ea911201a61"},{"fixed":"1fc7ca636cbd2cad29b42cc13c9fd0c681c6efee"},{"introduced":"bea6dc79db4d95c34b77ec27273d812aa64d65be"},{"fixed":"d776945b2dc41c0e609c56c1ef69863ab56856ed"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.2.0"},{"fixed":"7.4.12"},{"introduced":"8.0.0"},{"fixed":"8.0.12"}]}},{"type":"GIT","repo":"https://github.com/symfony/symfony","events":[{"introduced":"df8cd437bf489cf5aebe7e01e61daad120321c3b"},{"fixed":"275f5cbccbcc50205206f05e599c4f57009aadb8"},{"introduced":"2e913a829cfbbf9cb38b321bdff1806b44b192eb"},{"fixed":"06d3b2c9a8aeb5d8493738cc51e24f6a1215827c"},{"fixed":"4e0467e4e182cf2e704a3d9e1bc1a6be65d52ab8"}],"database_specific":{"extracted_events":[{"introduced":"7.2.0"},{"fixed":"7.4.12"},{"introduced":"8.0.0"},{"fixed":"8.0.12"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*"}}],"versions":["v8.0.11","v7.4.11","v7.4.0-BETA1","v8.0.9","v7.4.9","v8.0.8","v7.4.8","v8.0.6","v7.4.6","v8.0.4","v7.4.4","v8.0.3","v7.4.3","v8.0.1","v7.4.1","v7.4.0","v8.0.0","v7.4.0-RC2","v7.4.0-RC1","v7.3.0","v7.3.0-RC1","v7.3.0-BETA2","v7.3.0-BETA1","v7.2.1","v7.2.0-RC1","v7.2.0","v8.0.10","v8.0.7","v8.0.5","v8.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45755.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}