
Symfony の CVE-2026-47767 を掲載しました。過去に当てた CVE-2024-50340 の修正自体が不十分で、$_GET が空のままクエリ文字列から APP_ENV と APP_DEBUG を上書きできます。5.4系は 5.4.46 以上が対象、つまり前回… https://cve.autoarticles.net/cve/CVE-2026-47767
Post summary
The post announces Symfony CVE-2026-47767, noting that a prior fix was insufficient and that empty $_GET parameters can overwrite APP_ENV and APP_DEBUG, affecting versions 5.4.46 and above.
