Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5809-1 | symfony security update |
EUVD |
EUVD-2024-3230 | symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-9c3x-r3wp-mgxm | Symfony allows internal address and port enumeration by NoPrivateNetworkHttpClient |
Ubuntu USN |
USN-7272-1 | Symfony vulnerabilities |
Mon, 12 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sensiolabs
Sensiolabs httpclient |
|
| CPEs | cpe:2.3:a:sensiolabs:httpclient:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sensiolabs
Sensiolabs httpclient |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 07 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Title | Internal address and port enumeration allowed by NoPrivateNetworkHttpClient in symfony/http-client | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-07T15:26:33.540Z
Reserved: 2024-10-22T17:54:40.955Z
Link: CVE-2024-50342
Updated: 2024-11-07T15:26:29.969Z
Status : Analyzed
Published: 2024-11-06T21:15:05.963
Modified: 2026-01-12T17:45:24.250
Link: CVE-2024-50342
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:15:42Z
Debian DSA
EUVD
Github GHSA
Ubuntu USN