Symfony YAML Parser Stack Exhaustion Vulnerability Allowing Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in the Symfony YAML parser component. Prior to versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the parser could be exposed to attacker-controlled input that, when deeply nested mappings or sequences were introduced, caused both block-level and inline parsers to recurse without a depth limit. This unbounded recursion led to a stack exhaustion, crashing the PHP worker. The issue has been reported by Pietro Tirenna (Shielder) and fixed by Nicolas Grekas.

Impact

Exploitation of this vulnerability causes a stack overflow, leading to a crash of the PHP worker process.

Remediation

Users can update to Symfony versions 5.4.52, 6.4.40, 7.4.12, or 8.0.12 to address this vulnerability. The patch for this issue is available in the Symfony GitHub repository.

Added: Jul 15, 2026, 6:00 AM
Updated: Jul 15, 2026, 6:00 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
9.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.