Authentication Bypass Vulnerability in Auth0 Symfony SDK
CVE-2026-50157
6.5MEDIUM
What is CVE-2026-50157?
The Auth0 Symfony SDK permits the acceptance of OAuth 2.0 bearer access tokens through both the token URL query parameter and the Authorization header, posing a security risk. This dual acceptance can lead to exposure of tokens in server logs, browser history, or referrer data, making them susceptible to replay attacks against protected API endpoints. This vulnerability affects versions from 5.0.0-BETA0 up to 5.9.0 and has been resolved in version 5.9.0.
Affected Version(s)
symfony >= 5.0.0-BETA0, < 5.9.0
