{"id":"GHSA-fqc7-9xjw-jrh3","summary":"SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch","details":"### Description\n\nCVE-2024-50340 (GHSA-x8vp-gf4q-mw5j) addressed an issue where, with `register_argc_argv=On`, a crafted query string let an unauthenticated GET change the kernel environment and debug flag by feeding `--env`/`--no-debug` through `$_SERVER['argv']`. The fix shipped in `symfony/runtime` 5.4.46 / 6.4.14 / 7.1.7 gated the argv read on `empty($_GET)` as a proxy for \"is this a CLI invocation\".\n\nThat proxy is unsafe: `parse_str()` (which builds `$_GET`) and the web SAPI (which builds `$_SERVER['argv']` from the raw query when `register_argc_argv=On`) do not agree on every input, so an attacker can craft a query that leaves `$_GET` empty while `$_SERVER['argv']` carries the attacker's flags. `SymfonyRuntime::getInput()` then parses them, restoring the exact primitive CVE-2024-50340 was meant to prevent.\n\nPreconditions and impact match the original CVE: web SAPI, `register_argc_argv=On`, app booted through `symfony/runtime`; from an unauthenticated GET an attacker can flip `APP_ENV` and toggle `APP_DEBUG`.\n\n### Resolution\n\n`SymfonyRuntime` now gates the argv read on `isset($_SERVER['QUERY_STRING'])` rather than on `empty($_GET)`. `QUERY_STRING` is the same input the SAPI uses to build argv, so the security check and the thing it protects no longer parse different sources. Worker SAPIs (FrankenPHP / RoadRunner / Swoole) keep working because the runtime constructor runs once at boot when `QUERY_STRING` is unset.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/3228c3806ee511008bea19a95084d460b17e5d25) for branch 5.4.\n\n### Credits\n\nSymfonyRuntime would like to thank 0xEr3n for reporting the issue and Nicolas Grekas for providing the fix.","aliases":["CVE-2026-47767"],"modified":"2026-09-10T03:50:49.571562201Z","published":"2026-06-09T21:58:11Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-20","CWE-436","CWE-74"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-09T21:58:11Z"},"references":[{"type":"WEB","url":"https://github.com/symfony/symfony/security/advisories/GHSA-fqc7-9xjw-jrh3"},{"type":"PACKAGE","url":"https://github.com/symfony/symfony"}],"affected":[{"package":{"name":"symfony/runtime","ecosystem":"Packagist","purl":"pkg:composer/symfony/runtime"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.46"},{"fixed":"5.4.52"}]}],"versions":["v5.4.46"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fqc7-9xjw-jrh3/GHSA-fqc7-9xjw-jrh3.json"}},{"package":{"name":"symfony/runtime","ecosystem":"Packagist","purl":"pkg:composer/symfony/runtime"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.4.14"},{"fixed":"6.4.40"}]}],"versions":["v6.4.14","v6.4.22","v6.4.23","v6.4.24","v6.4.26","v6.4.30"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fqc7-9xjw-jrh3/GHSA-fqc7-9xjw-jrh3.json"}},{"package":{"name":"symfony/runtime","ecosystem":"Packagist","purl":"pkg:composer/symfony/runtime"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.1.7"},{"fixed":"7.4.12"}]}],"versions":["v7.1.7","v7.2.0","v7.2.0-BETA1","v7.2.0-BETA2","v7.2.0-RC1","v7.2.3","v7.2.7","v7.2.8","v7.3.0","v7.3.0-BETA1","v7.3.0-RC1","v7.3.1","v7.3.4","v7.3.8","v7.4.0","v7.4.0-BETA1","v7.4.0-BETA2","v7.4.0-RC1","v7.4.1","v7.4.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fqc7-9xjw-jrh3/GHSA-fqc7-9xjw-jrh3.json"}},{"package":{"name":"symfony/runtime","ecosystem":"Packagist","purl":"pkg:composer/symfony/runtime"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.0.12"}]}],"versions":["v8.0.0","v8.0.1","v8.0.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fqc7-9xjw-jrh3/GHSA-fqc7-9xjw-jrh3.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.46"},{"fixed":"5.4.52"}]}],"versions":["v5.4.46","v5.4.47","v5.4.48","v5.4.49","v5.4.50","v5.4.51"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fqc7-9xjw-jrh3/GHSA-fqc7-9xjw-jrh3.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.4.14"},{"fixed":"6.4.40"}]}],"versions":["v6.4.14","v6.4.15","v6.4.16","v6.4.17","v6.4.18","v6.4.19","v6.4.20","v6.4.21","v6.4.22","v6.4.23","v6.4.24","v6.4.25","v6.4.26","v6.4.27","v6.4.28","v6.4.29","v6.4.30","v6.4.31","v6.4.32","v6.4.33","v6.4.34","v6.4.35","v6.4.36","v6.4.37","v6.4.38","v6.4.39"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fqc7-9xjw-jrh3/GHSA-fqc7-9xjw-jrh3.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.1.7"},{"fixed":"7.4.12"}]}],"versions":["v7.1.10","v7.1.11","v7.1.7","v7.1.8","v7.1.9","v7.2.0","v7.2.0-BETA1","v7.2.0-BETA2","v7.2.0-RC1","v7.2.1","v7.2.2","v7.2.3","v7.2.4","v7.2.5","v7.2.6","v7.2.7","v7.2.8","v7.2.9","v7.3.0","v7.3.0-BETA1","v7.3.0-BETA2","v7.3.0-RC1","v7.3.1","v7.3.10","v7.3.11","v7.3.2","v7.3.3","v7.3.4","v7.3.5","v7.3.6","v7.3.7","v7.3.8","v7.3.9","v7.4.0","v7.4.0-BETA1","v7.4.0-BETA2","v7.4.0-RC1","v7.4.0-RC2","v7.4.0-RC3","v7.4.1","v7.4.10","v7.4.11","v7.4.2","v7.4.3","v7.4.4","v7.4.5","v7.4.6","v7.4.7","v7.4.8","v7.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fqc7-9xjw-jrh3/GHSA-fqc7-9xjw-jrh3.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.0.12"}]}],"versions":["v8.0.0","v8.0.1","v8.0.10","v8.0.11","v8.0.2","v8.0.3","v8.0.4","v8.0.5","v8.0.6","v8.0.7","v8.0.8","v8.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fqc7-9xjw-jrh3/GHSA-fqc7-9xjw-jrh3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}