Description
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missing isCacheKeySafe gate in the JSON:API and HAL item normalizers causes a cross-user attribute leak. #[ApiProperty(security: ...)] is evaluated per request to decide whether a property is exposed. The componentsCache arrays in ApiPlatform\JsonApi\Serializer\ItemNormalizer and ApiPlatform\Hal\Serializer\ItemNormalizer are keyed on $context['cache_key'], which is set unconditionally before delegating to the parent normalizer. The component structure (attributes, relationships, links) computed for one request can therefore be reused for a subsequent request whose user has a different set of accessible properties. A user with lower privileges may end up seeing the structure of properties that the security predicate would otherwise have hidden for them. This issue has been fixed in versions 4.1.29, 4.2.26, and 4.3.12.
Published: 2026-07-01
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing safety gate item normalizers of API Platform Core allows the componentsCache arrays to be keyed on a value that is not guaranteed to be safe. As a result, the attribute, relationship, and link structure produced for one request can be reused for a subsequent request belonging to a different user. The security predicates defined with #[ApiProperty(security: ...)] are a field should be exposed; because the cache is across users, a user with lower privileges may see the structure of properties that the security check would otherwise hide. This leads to accidental disclosure of information and matches CWE-524 (Information Leakage) and CWE-639 (Controlled Key).

Affected Systems

API Platform Core, API Platform HAL, and API Platform JSON:API packages are affected. All versions from 2.6.0 up to 4.1.28 inclusive, from 4.2.0 up to 4.2.25 inclusive, and from 4.3.0 up to 4.3.11 inclusive are vulnerable. The vulnerability is fixed in releases 4.1.29, 4.2.26, and 4.3.12.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate risk. The EPSS score is < 1%, indicating a very low but non‑zero likelihood of exploitation. The likely attack vector involves making API requests that trigger the normalizers, with an attacker controlling requests on behalf of two distinct users; based on the description, it is inferred that reusing the componentsCache across users can expose sensitive structure. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 22, 2026 at 14:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the fixed releases 4.1.29, 4.2.26, or 4.3.12 depending on your current major version.
  • Check the vendor's website or repository for any additional security advisories and apply updates promptly.
  • Maintain a monitoring process to detect unexpected data exposure in API responses, especially after deployment changes.

Generated by OpenCVE AI on July 22, 2026 at 14:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pjhx-3c3w-9v23 API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Api-platform
Api-platform api-platform/hal
Api-platform api-platform/json-api
Api-platform core
Vendors & Products Api-platform
Api-platform api-platform/hal
Api-platform api-platform/json-api
Api-platform core

Fri, 03 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missing isCacheKeySafe gate in the JSON:API and HAL item normalizers causes a cross-user attribute leak. #[ApiProperty(security: ...)] is evaluated per request to decide whether a property is exposed. The componentsCache arrays in ApiPlatform\JsonApi\Serializer\ItemNormalizer and ApiPlatform\Hal\Serializer\ItemNormalizer are keyed on $context['cache_key'], which is set unconditionally before delegating to the parent normalizer. The component structure (attributes, relationships, links) computed for one request can therefore be reused for a subsequent request whose user has a different set of accessible properties. A user with lower privileges may end up seeing the structure of properties that the security predicate would otherwise have hidden for them. This issue has been fixed in versions 4.1.29, 4.2.26, and 4.3.12.
Title API Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
Weaknesses CWE-524
CWE-639
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Api-platform Api-platform/hal Api-platform/json-api Core
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-02T12:20:09.370Z

Reserved: 2026-06-01T22:03:19.640Z

Link: CVE-2026-49858

cve-icon Vulnrichment

Updated: 2026-07-02T12:20:02.937Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T14:15:02Z

Weaknesses
  • CWE-524

    Use of Cache Containing Sensitive Information

  • CWE-639

    Authorization Bypass Through User-Controlled Key