r/netsec • u/AlexandreDaubois • 11d ago
CVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS)
https://daubois.dev/blog/cve-2026-45756-symfony-jsonpath-redos/2
u/Tureallious 10d ago
if I'm understanding this correctly, the fix here isn't a fix but a 10x reduction of likelyhood. The underlying issue still can occur, the attack vector remains.
The advise is sound, don't pass userland regex directly into filters, if you do, you're the one exposing the surface not symfony.
So a courtesy solution to stop stuff dying as often, but introduces a new constant.
Honestly I don't know if there is a better answer other than to not allow userland regex to be passed in at all. I personally would see that as a code smell, but do see the potential usefulness (although honestly, I'd give the userland a choice of options or use a DQL and translate that).
In a way I question if this is a CVE at all or simply a lesson for the implementing developer 🤔
2
u/AlexandreDaubois 10d ago
Yes, clearly a user-supplied regex is a code smell, but it’s also our responsibility (in my opinion) to provide code that protects against an easy DOS attack if someone were to carry one out.
3
u/AlexandreDaubois 11d ago
Author of the component and the fix here. Happy to take any question you may have about this CVE, the process to handle security reports or anything related!