{"id":"GHSA-ffq7-hh2j-r24p","summary":"Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter","details":"### Description\nApplications built with the Auth0 Symphony SDK, using the Authorizer security authenticator to protect HTTP routes may accept OAuth 2.0 bearer access tokens provided through a URL query parameter, in addition to the standard Authorization header, which may increase the risk of access token exposure and replay against protected API endpoints.\n\n### Resolution\nUpgrade auth0/symfony to version 5.9.0 or greater.\n\n### Acknowledgement\nOkta would like to thank Alex Yeara for their discovery.","aliases":["CVE-2026-50157"],"modified":"2026-07-28T05:30:29.612714243Z","published":"2026-07-14T19:31:23Z","database_specific":{"github_reviewed_at":"2026-07-14T19:31:23Z","nvd_published_at":null,"cwe_ids":["CWE-200","CWE-598"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/auth0/symfony/security/advisories/GHSA-ffq7-hh2j-r24p"},{"type":"WEB","url":"https://github.com/auth0/symfony/commit/172d1d3e0b9d1e93610d786118389a811179bc8a"},{"type":"WEB","url":"https://github.com/auth0/symfony/commit/bd1851b14ae15e99cbe87c96496cf25da025288a"},{"type":"PACKAGE","url":"https://github.com/auth0/symfony"},{"type":"WEB","url":"https://github.com/auth0/symfony/releases/tag/5.9.0"}],"affected":[{"package":{"name":"auth0/symfony","ecosystem":"Packagist","purl":"pkg:composer/auth0/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0-BETA0"},{"fixed":"5.9.0"}]}],"versions":["5.0.0","5.0.0-BETA0","5.0.0-BETA1","5.1.0","5.2.0","5.2.1","5.2.2","5.2.3","5.3.0","5.3.1","5.4.0","5.4.1","5.5.0","5.6.0","5.7.0","5.8.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 5.8.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-ffq7-hh2j-r24p/GHSA-ffq7-hh2j-r24p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}