Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-50157— Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK

Quick assessment

Affected
auth0 symfony
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Auth0 Symfony 是用于 Auth0 身份验证和管理 API 的 Symfony SDK。在 5.0.0-BETA0 到 5.9.0 版本中, 安全认证器中的 和 方法可能会接受来自查询参数中 token URL 的 OAuth 2.0 Bearer 访问令牌,同时也接受来自 Authorization 请求头的令牌,用于受保护的 HTTP 路由。通过查询字符串传递的令牌可能会记录在服务器日志、浏览器历史记录或 Referrer(来源页)数据中,随后可能被重放攻击(replay)用于访问受保护的 API

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1040 · Network Sniffing

Affected Version Matrix 1

VendorProduct Version RangeStatus
auth0 symfony >= 5.0.0-BETA0, < 5.9.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-50157

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK
Source: CVE Program / CVE List V5
Vulnerability Description
Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as the Authorization header for protected HTTP routes. Query-string tokens can be recorded in server logs, browser history, or referrer data and then replayed against protected API endpoints. This issue is fixed in version 5.9.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过GET请求中的查询字符串导致的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
auth0 symfony >= 5.0.0-BETA0, < 5.9.0 -

II. Public POCs for CVE-2026-50157

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-50157

登录查看更多情报信息。

Patches & Fixes for CVE-2026-50157 (1)

Vendor Advisories for CVE-2026-50157 (1)

Vendor Pages for CVE-2026-50157 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-50157

No comments yet


Leave a comment