{"id":"GHSA-38cx-cq6f-5755","summary":"Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient","details":"### Description\n\n`Symfony\\Component\\HttpClient\\NoPrivateNetworkHttpClient` is documented as a decorator that blocks requests to private networks by default. The list of blocked subnets (`Symfony\\Component\\HttpFoundation\\IpUtils::PRIVATE_SUBNETS` on 6.4+, a private constant in `NoPrivateNetworkHttpClient` on 5.4) enumerates RFC1918, loopback, link-local and IPv4-mapped IPv6 (`::ffff:0:0/96`) prefixes, but omits the remaining IPv6 transition forms that can embed a private IPv4 destination: 6to4 (`2002::/16`, RFC 3056), Teredo (`2001::/32`, RFC 4380), NAT64 (`64:ff9b::/96`, RFC 6052 and `64:ff9b:1::/48`, RFC 8215) and IPv4-compatible IPv6 (`::/96`, RFC 4291 §2.5.5.1).\n\n`IpUtils::checkIp6()` is a pure bitwise CIDR comparison against the constants list and never extracts the embedded IPv4, so an attacker who can supply a URL writes the loopback / RFC1918 IPv4 target as e.g. `http://[2002:7f00:1::]/` (6to4 → 127.0.0.1), `http://[64:ff9b::7f00:1]/` (NAT64 → 127.0.0.1), `http://[::7f00:1]/` (IPv4-compatible → 127.0.0.1) or `http://[2001::1]/` (Teredo). `IpUtils::isPrivateIp()` returns `false` and `NoPrivateNetworkHttpClient` dispatches the request.\n\nReal-world reachability of the embedded IPv4 depends on the deploy's IPv6 routing (6to4 tunnel interface, upstream NAT64 gateway, kernel handling of IPv4-compatible addresses), but the security boundary the decorator promises — the dispatch decision — is crossed regardless of whether the packet ultimately lands on the embedded IPv4.\n\n### Resolution\n\nThe private-subnet list now includes `::/96`, `2002::/16`, `2001::/32`, `64:ff9b::/96` and `64:ff9b:1::/48`. Blanket blocking of these prefixes matches the policy applied by Chromium and Mozilla's Private Network Access; server-side HTTPS APIs are not legitimately published on these prefixes.\n\nThe patches for this issue are available [here](https://github.com/symfony/symfony/commit/82765368cf74177c36613575182f168a2eb765b2) for branch 5.4 and [here](https://github.com/symfony/symfony/commit/85b831555be8ea1f43bf01078afe87bc4c92f65e) for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1).\n\n### Credits\n\nSymfony would like to thank tonghuaroot for reporting the issue and Nicolas Grekas for providing the fix.","aliases":["CVE-2026-48736"],"modified":"2026-09-10T03:51:07.914923830Z","published":"2026-06-15T17:31:28Z","database_specific":{"cwe_ids":["CWE-184","CWE-918"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-15T17:31:28Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/symfony/symfony/security/advisories/GHSA-38cx-cq6f-5755"},{"type":"WEB","url":"https://github.com/symfony/symfony/commit/82765368cf74177c36613575182f168a2eb765b2"},{"type":"WEB","url":"https://github.com/symfony/symfony/commit/85b831555be8ea1f43bf01078afe87bc4c92f65e"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-client/CVE-2026-48736.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-foundation/CVE-2026-48736.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2026-48736.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/symfony"},{"type":"WEB","url":"https://symfony.com/cve-2026-48736"}],"affected":[{"package":{"name":"symfony/http-client","ecosystem":"Packagist","purl":"pkg:composer/symfony/http-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.0"},{"fixed":"5.4.53"}]}],"versions":["v5.4.0","v5.4.1","v5.4.11","v5.4.12","v5.4.13","v5.4.14","v5.4.15","v5.4.16","v5.4.17","v5.4.19","v5.4.2","v5.4.20","v5.4.21","v5.4.22","v5.4.23","v5.4.24","v5.4.25","v5.4.26","v5.4.29","v5.4.3","v5.4.31","v5.4.34","v5.4.35","v5.4.36","v5.4.37","v5.4.38","v5.4.39","v5.4.40","v5.4.41","v5.4.42","v5.4.43","v5.4.44","v5.4.45","v5.4.46","v5.4.47","v5.4.48","v5.4.49","v5.4.5","v5.4.7","v5.4.8","v5.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-38cx-cq6f-5755/GHSA-38cx-cq6f-5755.json"}},{"package":{"name":"symfony/http-foundation","ecosystem":"Packagist","purl":"pkg:composer/symfony/http-foundation"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.4.0"},{"fixed":"6.4.41"}]}],"versions":["v6.4.0","v6.4.10","v6.4.12","v6.4.13","v6.4.14","v6.4.15","v6.4.16","v6.4.18","v6.4.2","v6.4.21","v6.4.22","v6.4.23","v6.4.24","v6.4.25","v6.4.26","v6.4.28","v6.4.29","v6.4.3","v6.4.30","v6.4.31","v6.4.32","v6.4.33","v6.4.34","v6.4.35","v6.4.4","v6.4.7","v6.4.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-38cx-cq6f-5755/GHSA-38cx-cq6f-5755.json"}},{"package":{"name":"symfony/http-foundation","ecosystem":"Packagist","purl":"pkg:composer/symfony/http-foundation"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.4.13"}]}],"versions":["v7.0.0","v7.0.10","v7.0.3","v7.0.4","v7.0.6","v7.0.7","v7.0.8","v7.1.0","v7.1.0-BETA1","v7.1.0-RC1","v7.1.1","v7.1.10","v7.1.11","v7.1.3","v7.1.5","v7.1.6","v7.1.7","v7.1.8","v7.1.9","v7.2.0","v7.2.0-BETA1","v7.2.0-BETA2","v7.2.0-RC1","v7.2.2","v7.2.3","v7.2.5","v7.2.6","v7.2.7","v7.2.8","v7.2.9","v7.3.0","v7.3.0-BETA1","v7.3.0-BETA2","v7.3.0-RC1","v7.3.1","v7.3.10","v7.3.11","v7.3.2","v7.3.3","v7.3.4","v7.3.5","v7.3.6","v7.3.7","v7.3.8","v7.3.9","v7.4.0","v7.4.0-BETA1","v7.4.0-BETA2","v7.4.0-RC1","v7.4.1","v7.4.3","v7.4.4","v7.4.5","v7.4.6","v7.4.7","v7.4.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-38cx-cq6f-5755/GHSA-38cx-cq6f-5755.json"}},{"package":{"name":"symfony/http-foundation","ecosystem":"Packagist","purl":"pkg:composer/symfony/http-foundation"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.0.13"}]}],"versions":["v8.0.0","v8.0.1","v8.0.3","v8.0.4","v8.0.5","v8.0.6","v8.0.7","v8.0.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-38cx-cq6f-5755/GHSA-38cx-cq6f-5755.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.0"},{"fixed":"5.4.53"}]}],"versions":["v5.4.0","v5.4.1","v5.4.10","v5.4.11","v5.4.12","v5.4.13","v5.4.14","v5.4.15","v5.4.16","v5.4.17","v5.4.18","v5.4.19","v5.4.2","v5.4.20","v5.4.21","v5.4.22","v5.4.23","v5.4.24","v5.4.25","v5.4.26","v5.4.27","v5.4.28","v5.4.29","v5.4.3","v5.4.30","v5.4.31","v5.4.32","v5.4.33","v5.4.34","v5.4.35","v5.4.36","v5.4.37","v5.4.38","v5.4.39","v5.4.4","v5.4.40","v5.4.41","v5.4.42","v5.4.43","v5.4.44","v5.4.45","v5.4.46","v5.4.47","v5.4.48","v5.4.49","v5.4.5","v5.4.50","v5.4.51","v5.4.52","v5.4.6","v5.4.7","v5.4.8","v5.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-38cx-cq6f-5755/GHSA-38cx-cq6f-5755.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.4.0"},{"fixed":"6.4.41"}]}],"versions":["v6.4.0","v6.4.1","v6.4.10","v6.4.11","v6.4.12","v6.4.13","v6.4.14","v6.4.15","v6.4.16","v6.4.17","v6.4.18","v6.4.19","v6.4.2","v6.4.20","v6.4.21","v6.4.22","v6.4.23","v6.4.24","v6.4.25","v6.4.26","v6.4.27","v6.4.28","v6.4.29","v6.4.3","v6.4.30","v6.4.31","v6.4.32","v6.4.33","v6.4.34","v6.4.35","v6.4.36","v6.4.37","v6.4.38","v6.4.39","v6.4.4","v6.4.40","v6.4.5","v6.4.6","v6.4.7","v6.4.8","v6.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-38cx-cq6f-5755/GHSA-38cx-cq6f-5755.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.4.13"}]}],"versions":["v7.0.0","v7.0.1","v7.0.10","v7.0.2","v7.0.3","v7.0.4","v7.0.5","v7.0.6","v7.0.7","v7.0.8","v7.0.9","v7.1.0","v7.1.0-BETA1","v7.1.0-RC1","v7.1.1","v7.1.10","v7.1.11","v7.1.2","v7.1.3","v7.1.4","v7.1.5","v7.1.6","v7.1.7","v7.1.8","v7.1.9","v7.2.0","v7.2.0-BETA1","v7.2.0-BETA2","v7.2.0-RC1","v7.2.1","v7.2.2","v7.2.3","v7.2.4","v7.2.5","v7.2.6","v7.2.7","v7.2.8","v7.2.9","v7.3.0","v7.3.0-BETA1","v7.3.0-BETA2","v7.3.0-RC1","v7.3.1","v7.3.10","v7.3.11","v7.3.2","v7.3.3","v7.3.4","v7.3.5","v7.3.6","v7.3.7","v7.3.8","v7.3.9","v7.4.0","v7.4.0-BETA1","v7.4.0-BETA2","v7.4.0-RC1","v7.4.0-RC2","v7.4.0-RC3","v7.4.1","v7.4.10","v7.4.11","v7.4.12","v7.4.2","v7.4.3","v7.4.4","v7.4.5","v7.4.6","v7.4.7","v7.4.8","v7.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-38cx-cq6f-5755/GHSA-38cx-cq6f-5755.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.0.13"}]}],"versions":["v8.0.0","v8.0.1","v8.0.10","v8.0.11","v8.0.12","v8.0.2","v8.0.3","v8.0.4","v8.0.5","v8.0.6","v8.0.7","v8.0.8","v8.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-38cx-cq6f-5755/GHSA-38cx-cq6f-5755.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}