CVE-2026-45133·PHP vulnerability
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parsers to recurse without a depth limit. A crafted document exhausts the PHP stack and crashes the worker. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
- Severity
- high
- Software
- PHP
- Fixed in
- 8.0.12
- Published
- 2026-07-14
Affected versions
From: 8.0.0
Until: 8.0.12
Fixed in: 8.0.12
How to fix this CVE
Update PHP and Symfony to versions 8.0.12 or later to resolve a stack exhaustion vulnerability in the YAML parser. Applications using Symfony 8.0.0 through 8.0.11 with untrusted YAML input are at risk of denial of service attacks. Upgrade immediately and test your application after patching.
sudo dnf update phpDefensia detects this vulnerability
WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement rate limiting and request size limits on endpoints that parse user-supplied YAML input. Consider rejecting YAML documents exceeding a reasonable depth threshold (e.g., nesting level > 50) at the WAF layer to prevent parser exhaustion before it reaches the application.How to check if you are affected
- Step 1: Check your PHP version by running `php -v` and confirm it is 8.0.0 through 8.0.11
- Step 2: Verify Symfony version in your application by checking `composer show symfony/symfony` or examining `vendor/symfony/symfony/VERSION` file
- Step 3: Search application logs for PHP Fatal errors with 'stack overflow' or 'maximum function nesting level' messages around the time of suspected attacks
- Step 4: After patching, run `php -v` again to confirm version is 8.0.12 or higher, then run your test suite to verify application stability
FAQ
What is CVE-2026-45133?
This vulnerability affects the Symfony YAML parser, which lacks recursion depth limits when processing deeply nested YAML mappings or sequences. An attacker can craft a malicious YAML document that causes unbounded recursion, exhausting the PHP stack and crashing the application worker.
Is CVE-2026-45133 being actively exploited?
No, this vulnerability is not currently listed on the CISA KEV catalog and has no known public exploits, though the high CVSS score (7.5) warrants prompt patching.
What versions of PHP are affected by CVE-2026-45133?
Symfony versions 8.0.0 through 8.0.11 are affected. The vulnerability is fixed in Symfony 8.0.12 and also patched in earlier major versions (5.4.52, 6.4.40, 7.4.12).
How do I check if my server is vulnerable to CVE-2026-45133?
Run `composer show symfony/symfony | grep version` to display your installed Symfony version, then verify it is not in the range 8.0.0–8.0.11.
Does Defensia detect CVE-2026-45133?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PHP and Symfony are installed on a monitored server, CVE-2026-45133 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-45133. Free for 1 server.
Get started free