Description
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's AbstractItemNormalizer does not validate the resource type returned when resolving relation IRIs, allowing type confusion where a resource of an unintended type can be silently assigned to a relation property. An attacker who can submit write requests (POST/PUT/PATCH) to an API Platform endpoint with writable relations can supply a relation IRI pointing to a resource of a different type than the relation's declared class. Because getResourceFromIri() does not pass an $operation to IriConverter::getResourceFromIri(), the is_a type guard at IriConverter.php:86 is skipped. For untyped relation properties (legacy @var-only style), the wrong-typed object is silently assigned, corrupting invariants and potentially feeding downstream logic that assumes the declared type (CWE-843). For typed properties (modern PHP 8.x), the substitution is blocked by Symfony's PropertyAccessor with an InvalidTypeException. This issue has been fixed in versions 4.1.30, 4.2.26 and 4.3.12.
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The serializer in API Platform Core fails to confirm that the class of a resource resolved from an IRI matches the relation’s declared type, allowing a crafted IRI to reference an unintended resource type. An attacker who can send write requests (POST/PUT/PATCH) to an endpoint whose relations are writable may supply such an IRI. For legacy untyped properties the framework silently assigns the wrong‑typed object, corrupting data consistency and potentially feeding downstream logic that expects the declared type. For modern typed properties Symfony’s PropertyAccessor blocks the substitution and throws an InvalidTypeException, but the silent corruption risk remains for legacy code.

Affected Systems

API Platform Core is the affected product. Versions prior to 4.1.30, 4.2.26 and 4.3.12 are vulnerable; releases equal to or newer than those values contain the fix.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % shows a very low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to send a crafted IRI in a writable API request; successful exploitation can silently corrupt data on systems that use legacy untyped relation properties, or trigger a type mismatch exception on typed properties. The attack vector remains confined to the application layer and does not provide remote code execution or broader system compromise.

Generated by OpenCVE AI on August 1, 2026 at 22:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade API Platform Core to version 4.1.30, 4.2.26, 4.3.12 or later.
  • If upgrading is not possible, disable write permissions on API endpoints that expose writable relations.
  • Implement server‑side validation to verify that the type of the object resolved from an IRI matches the expected relation class before assignment.

Generated by OpenCVE AI on August 1, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9rjg-x2p2-h68h API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
History

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Api-platform
Api-platform core
Vendors & Products Api-platform
Api-platform core

Wed, 01 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's AbstractItemNormalizer does not validate the resource type returned when resolving relation IRIs, allowing type confusion where a resource of an unintended type can be silently assigned to a relation property. An attacker who can submit write requests (POST/PUT/PATCH) to an API Platform endpoint with writable relations can supply a relation IRI pointing to a resource of a different type than the relation's declared class. Because getResourceFromIri() does not pass an $operation to IriConverter::getResourceFromIri(), the is_a type guard at IriConverter.php:86 is skipped. For untyped relation properties (legacy @var-only style), the wrong-typed object is silently assigned, corrupting invariants and potentially feeding downstream logic that assumes the declared type (CWE-843). For typed properties (modern PHP 8.x), the substitution is blocked by Symfony's PropertyAccessor with an InvalidTypeException. This issue has been fixed in versions 4.1.30, 4.2.26 and 4.3.12.
Title API Platform Core: Missing IRI type check enables resource type confusion
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Api-platform Core
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-02T15:50:25.125Z

Reserved: 2026-06-11T21:46:52.380Z

Link: CVE-2026-54164

cve-icon Vulnrichment

Updated: 2026-07-02T15:49:54.792Z

cve-icon NVD

Status : Deferred

Published: 2026-07-01T20:17:10.657

Modified: 2026-07-02T17:54:15.243

Link: CVE-2026-54164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T22:45:03Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')