CVE-2024-50340Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.14, and 7.1.7 the `SymfonyRuntime` now ignores the `argv` values for non-SAPI PHP runtimes. All users are advised to upgrade. There are no known workarounds for this vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-09: 1Technical Details · 2026-08-09: 108-09
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • takenaka hiroya@Joe_Biden_ja
    Disclosure

    Symfony の CVE-2026-47767 を掲載しました。過去に当てた CVE-2024-50340 の修正自体が不十分で、$_GET が空のままクエリ文字列から APP_ENV と APP_DEBUG を上書きできます。5.4系は 5.4.46 以上が対象、つまり前回… https://cve.autoarticles.net/cve/CVE-2026-47767

    Post summary

    The post announces Symfony CVE-2026-47767, noting that a prior fix was insufficient and that empty $_GET parameters can overwrite APP_ENV and APP_DEBUG, affecting versions 5.4.46 and above.

    0000077
    562 followersView on X

Explore more