Symfony Mailjet Mailer and LOX24 Notifier Webhook Secret Verification Vulnerability

Vulnerability

A vulnerability exists in the Symfony Mailjet mailer bridge and LOX24 notifier bridge webhook parsers, prior to versions 6.4.40, 7.4.12, and 8.0.12. The parsers received configured webhook secrets but failed to verify them, allowing unauthenticated POST requests to inject forged event payloads. This lack of verification could lead to the corruption of suppression lists and manipulation of delivery metrics.

Impact

Exploitation of this vulnerability allows for unauthenticated injection of forged webhook event payloads, which can corrupt suppression lists and fraudulently alter delivery metrics.

Reproduction

To reproduce this vulnerability, configure a webhook secret for either the Mailjet mailer or LOX24 notifier bridge. Then, send a POST request to the webhook endpoint without including the expected authentication credentials or token. The webhook parser will accept the request and process the injected event payload, demonstrating the lack of secret verification.

Remediation

This vulnerability has been patched in Symfony versions 6.4.40, 7.4.12, and 8.0.12. Users should update to these versions.

Added: Jul 15, 2026, 5:58 AM
Updated: Jul 15, 2026, 5:58 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.4
remediation
0.0
relevance
9.2
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.