CVE-2025-64500 | Symfony up to 5.4.49/6.4.28/7.3.6 Request PATH_INFO non-canonical url paths for authorization decisions (GHSA-3rg7-wf37-54rm)
A vulnerability categorized as critical has been discovered in Symfony up to 5.4.49/6.4.28/7.3.6. This issue affects the function Request. Such manipulation of the argument PATH_INFO leads to use of non-canonical url paths for authorization decisions.
This vulnerability is referenced as CVE-2025-64500. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.