Impact
The TwilioRequestParser in Symfony parses incoming Twilio webhook events. Prior to the security fix in versions 6.4.40, 7.4.12, and 8.0.12, it accepted the configured webhook secret but failed to verify the X‑Twilio‑Signature HMAC header, allowing unauthenticated POST requests to inject forged Twilio status payloads. This missing authentication (CWE‑306) and improper handling of sensitive data (CWE‑347) lets attackers alter status updates or trigger unintended logic without authorization, potentially compromising integrity or causing denial of service.
Affected Systems
Affected depend on the Twilio Notifier component and run a version earlier than 6.4.40, 7.4.12, or 8.0.12. The issue is present in the Symfony core and the symfony:twilio-notifier package, which many PHP developers use to build webhook handlers for Twilio services.
Risk and Exploitability
The vulnerability is rated CVSS 6.9, placing it in the moderate severity range. The EPSS probability of exploitation is 2%, indicating a low likelihood of exploitation in production environments at present. Because the issue is not tracked in the CISA KEV list, no known widespread exploits have been documented. Attackers can exploit the flaw by sending unauthenticated HTTP POST requests to a Symfony application hosting a Twilio webhook endpoint, as the parser does not verify the X‑Twilio‑Signature HMAC. Successful exploitation allows an attacker to inject forged Twilio status payloads, potentially leading to unintended state changes or logic execution within the application.
OpenCVE Enrichment
Github GHSA