Known Vulnerabilities for Security-http by Symfony
Listed below are 10 of the newest known vulnerabilities associated with "Security-http" by "Symfony".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-69257 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP secur... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-66829 json | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a r... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-66753 json | tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0... | Not Provided | 2026-07-28 | 2026-07-28 |
| CVE-2026-66746 json | Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrar... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-63771 json | Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injec... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-63687 json | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without ex... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-63220 json | CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarde... | Not Provided | 2026-07-31 | 2026-07-31 |
| CVE-2026-62899 json | Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to b... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-61275 json | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Role Based Security). Supported versi... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-61246 json | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty... | Not Provided | 2026-07-22 | 2026-07-23 |