CVE-2026-49209
Last modified
CVE-2026-49209 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-request for each entry; because the array size is never bounded, an authenticated client can submit a single _batch request containing thousands of actions and exhaust CPU, memory, and database connections on the application server. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-request for each entry; because the array size is never bounded, an authenticated client can submit a single _batch request containing thousands of actions and exhaust CPU, memory, and database connections on the application server. This issue is fixed in versions 2.36.0 and 3.1.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Symfony | Ux | >= 2.5.0, < 2.36.0 |
| Symfony | Ux | 3.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-49209?
How severe is CVE-2026-49209?
How do I fix CVE-2026-49209?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-49201The upload.cgi binary, responsible for processing device bac…9.8
- CVE-2026-49202Internal multimedia session archives are accessible without …8.6
- CVE-2026-49203Crucial management API endpoints for cellular eSIM allocatio…8.3
- CVE-2026-49204Leftover debug modules contain fixed credentials for interna…6.5
- CVE-2026-49205phpMyFAQ is an open source FAQ web application. Versions pri…6.5
- CVE-2026-49208Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0…5.3
- CVE-2026-4921IBM Guardium Data Protection 12.2 could allow an administrat…2.7
- CVE-2026-49210Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0…6.1
- CVE-2026-49211Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0…7.5
- CVE-2026-49212Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0…7.5
- CVE-2026-49213TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot'…8.1
- CVE-2026-49214guzzlehttp/psr7 is a PSR-7 HTTP message library implementati…5.3
Are you affected by CVE-2026-49209?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
