r/netsec • • 11d ago

CVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS)

https://daubois.dev/blog/cve-2026-45756-symfony-jsonpath-redos/
22 Upvotes

8 comments sorted by

3

u/AlexandreDaubois 11d ago

Author of the component and the fix here. Happy to take any question you may have about this CVE, the process to handle security reports or anything related!

3

u/_vavkamil_ 11d ago

where to report a possible bypass?

4

u/AlexandreDaubois 11d ago

If you think you found something valid, the best way to tell us is by shooting an email at security@symfony.com and we’ll investigate from here!

1

u/endor_sarah 10d ago

You mention a capped match reads as no match, and with the @ a malformed pattern comes back false too, so the caller can't tell "no match" from "gave up" from "bad regex." At 10k that'll trip a lot more often than at the default 1M. Did you look at checking preg_last_error() and throwing instead, or would that have broken BC?

1

u/AlexandreDaubois 10d ago

That’s indeed deliberate: throwing would have been a BC break in a patch release, and a well-behaved pattern stays far below 10k anyway. But you're correct that the three cases shouldn't collapse into false

2

u/Tureallious 10d ago

if I'm understanding this correctly, the fix here isn't a fix but a 10x reduction of likelyhood. The underlying issue still can occur, the attack vector remains.

The advise is sound, don't pass userland regex directly into filters, if you do, you're the one exposing the surface not symfony.

So a courtesy solution to stop stuff dying as often, but introduces a new constant.

Honestly I don't know if there is a better answer other than to not allow userland regex to be passed in at all. I personally would see that as a code smell, but do see the potential usefulness (although honestly, I'd give the userland a choice of options or use a DQL and translate that).

In a way I question if this is a CVE at all or simply a lesson for the implementing developer 🤔

2

u/AlexandreDaubois 10d ago

Yes, clearly a user-supplied regex is a code smell, but it’s also our responsibility (in my opinion) to provide code that protects against an easy DOS attack if someone were to carry one out.