CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-ffq7-hh2j-r24p: Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter

mediumCVSS 6.5CVE-2026-50157
Description Applications built with the Auth0 Symphony SDK, using the Authorizer security authenticator to protect HTTP routes may accept OAuth 2.0 bearer access tokens provided through a URL query parameter, in addition to the standard Authorization header, which may increase the risk of access token exposure and replay against protected API endpoints. Resolution Upgrade auth0/symfony to version 5.9.0 or greater. Acknowledgement Okta would like to thank Alex Yeara for their discovery.

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 6.5
Published
2026-07-14
Last updated
2026-07-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-ffq7-hh2j-r24p

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-50157coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories