Description
Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as the Authorization header for protected HTTP routes. Query-string tokens can be recorded in server logs, browser history, or referrer data and then replayed against protected API endpoints. This issue is fixed in version 5.9.0.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized API access via processed bearer token in URL query parameters
Action: Immediate Patch
AI Analysis

Impact

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From version 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens supplied in the token URL query parameter as well as from the Authorization header for protected HTTP routes. Because tokens can be logged in server logs, browser history, or referrer data, an attacker who captures a token could replay it against protected API endpoints, gaining unauthorized access. The weakness is identified as CWE-598 and is resolved in version 5.9.0.

Affected Systems

Auth0 Symfony, a Symfony SDK for Auth0 Authentication and Management APIs, is impacted. Versions from 5.0.0-BETA0 through 5.8.x (inclusive) allow the query-string token behavior. Version 5.9.0 and later address the issue, so those are not affected.

Risk and Exploitability

Based on the description, it is inferred that the most likely attack vector involves sending an HTTP request with a bearer token in the query string to a protected route. The CVSS score of 6.5 indicates a medium impact, and the EPSS score of < 1% signals an extremely low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The token can be captured from logs or history for replay, allowing an attacker to hijack sessions or perform actions on the holder's behalf. The vulnerability applies only to affected versions and is mitigated by upgrading to 5.9.0 or later.

Generated by OpenCVE AI on September 21, 2026 at 00:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Auth0 Symfony SDK to version 5.9.0 or later, where the query‑string token handling has been removed.
  • If upgrading is not immediately possible, configure the application or reverse proxy to strip or reject bearer tokens supplied in URL query parameters for protected routes.
  • Review and sanitize server logs, browser history, and referrer data to remove any stored bearer tokens before they can be abused.

Generated by OpenCVE AI on September 21, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-ffq7-hh2j-r24p Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter
History

Tue, 15 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Auth0
Auth0 symfony
Vendors & Products Auth0
Auth0 symfony

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as the Authorization header for protected HTTP routes. Query-string tokens can be recorded in server logs, browser history, or referrer data and then replayed against protected API endpoints. This issue is fixed in version 5.9.0.
Title Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK
Weaknesses CWE-598
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:06:21.452Z

Reserved: 2026-06-03T20:54:20.432Z

Link: CVE-2026-50157

cve-icon Vulnrichment

Updated: 2026-09-14T19:20:55.595Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:17:49.663

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-50157

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses
  • CWE-598

    Use of HTTP Request With Sensitive Query String