{"id":"CVE-2026-48736","summary":"Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient","details":"Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.","aliases":["GHSA-38cx-cq6f-5755"],"modified":"2026-07-17T03:47:04.722055195Z","published":"2026-07-14T19:09:30.260Z","related":["CGA-3ffj-v336-69mg"],"database_specific":{"cwe_ids":["CWE-184","CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48736.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/symfony/symfony/releases/tag/v5.4.53"},{"type":"WEB","url":"https://github.com/symfony/symfony/releases/tag/v6.4.41"},{"type":"WEB","url":"https://github.com/symfony/symfony/releases/tag/v7.4.13"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48736.json"},{"type":"ADVISORY","url":"https://github.com/symfony/symfony/security/advisories/GHSA-38cx-cq6f-5755"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48736"},{"type":"FIX","url":"https://github.com/symfony/symfony/commit/82765368cf74177c36613575182f168a2eb765b2"},{"type":"FIX","url":"https://github.com/symfony/symfony/commit/85b831555be8ea1f43bf01078afe87bc4c92f65e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/symfony/security-http","events":[{"introduced":"3fa1dcbde86f12454a78c69e9d1a6c3dca776ea4"},{"fixed":"dc6de50b41b636c4405d748015301e12e58e6b13"},{"introduced":"1b49ad8e9f2c3ceec011d67ac09e774e4107416b"},{"fixed":"1a01cd7a6313d5a375480e0d1d4a0ddf834ae12b"},{"introduced":"f84d7d3c93e6a884908402775199b1f7d55c7be1"},{"fixed":"da3c28025a664e6a88e1af104a74457d99301161"},{"introduced":"bea6dc79db4d95c34b77ec27273d812aa64d65be"},{"fixed":"ca895c1303cc1d290f190cd7301d48fcef9e73e5"}],"database_specific":{"cpe":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.4.0"},{"fixed":"5.4.43"},{"introduced":"6.4.0"},{"fixed":"6.4.41"},{"introduced":"7.0.0"},{"fixed":"7.4.13"},{"introduced":"8.0.0"},{"fixed":"8.0.13"}],"source":"CPE_RANGE"}},{"type":"GIT","repo":"https://github.com/symfony/symfony","events":[{"introduced":"94eb8a9c657257360b65a6ec4a6a64fb0551fe6a"},{"fixed":"4a4c52e875f544f502a3b63986088315d88ff840"},{"introduced":"228a275ddcc1a4301fc8865945c0686b56658135"},{"fixed":"14ff191853ad60d640c0853b4f17fc0f3b4de0ae"},{"introduced":"d78c5f403d7ee794993660b1d5155536edd36fc1"},{"fixed":"d9981b6e4c77b97472845a9b7fcba5507208aacc"},{"introduced":"2e913a829cfbbf9cb38b321bdff1806b44b192eb"},{"fixed":"ad82cb517407582bb697e079c5ee62bf8b7af3b7"},{"fixed":"82765368cf74177c36613575182f168a2eb765b2"},{"fixed":"85b831555be8ea1f43bf01078afe87bc4c92f65e"},{"fixed":"6436e377f7a82a1e7b120da519c7c96a154ece2a"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.4.0"},{"fixed":"5.4.43"},{"introduced":"6.4.0"},{"fixed":"6.4.41"},{"introduced":"7.0.0"},{"fixed":"7.4.13"},{"introduced":"8.0.0"},{"fixed":"8.0.13"}]}}],"versions":["v8.0.12","v7.4.12","v6.4.40","v6.4.39","v8.0.11","v7.4.11","v7.4.0-BETA1","v8.0.9","v7.4.9","v6.4.34","v8.0.8","v7.4.8","v8.0.6","v7.4.6","v6.4.31","v8.0.4","v7.4.4","v8.0.3","v7.4.3","v8.0.1","v7.4.1","v6.4.30","v7.4.0","v8.0.0","v7.4.0-RC2","v7.4.0-RC1","v6.4.26","v6.4.25","v6.4.24","v6.4.23","v7.3.0","v6.4.22","v7.3.0-RC1","v7.3.0-BETA2","v7.3.0-BETA1","v6.4.21","v6.4.19","v6.4.18","v7.2.1","v6.4.15","v7.2.0-RC1","v7.2.0","v7.2.0-BETA2","v6.4.14","v7.2.0-BETA1","v6.4.13","v6.4.12","v6.4.11","v6.4.9","v5.4.41","v6.4.8","v5.4.40","v7.1.0-RC1","v7.1.0","v7.1.0-BETA1","v6.4.7","v5.4.39","v6.4.4","v5.4.38","v5.4.36","v5.4.35","v6.4.3","v7.0.1","v6.4.0-RC2","v6.4.0","v5.4.31","v7.0.0-RC2","v7.0.0","v5.4.30","v5.4.28","v5.4.26","v5.4.23","v5.4.22","v5.4.21","v5.4.20","v5.4.19","v5.4.17","v5.4.15","v5.4.13","v5.4.11","v5.4.12","v5.4.10","v5.4.9","v5.4.8","v5.4.5","v5.4.3","v5.4.2","v5.4.0","v5.4.52","v5.4.51","v6.4.38","v8.0.10","v6.4.37","v6.4.36","v8.0.7","v6.4.35","v8.0.5","v6.4.33","v6.4.32","v5.4.50","v8.0.2","v6.4.29","v5.4.49","v6.4.28","v6.4.27","v6.4.20","v6.4.17","v6.4.16","v5.4.48","v5.4.47","v5.4.46","v5.4.45","v5.4.44","v5.4.43","v6.4.10","v5.4.42","v6.4.6","v6.4.5","v5.4.37","v6.4.2","v5.4.34","v6.4.1","v5.4.33","v5.4.32","v5.4.29","v5.4.27","v5.4.25","v5.4.24","v5.4.18","v5.4.16","v5.4.14","v5.4.7","v5.4.6","v5.4.4","v5.4.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48736.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N"}]}