CVE-2026-50157
Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter
Description
### Description Applications built with the Auth0 Symphony SDK, using the Authorizer security authenticator to protect HTTP routes may accept OAuth 2.0 bearer access tokens provided through a URL query parameter, in addition to the standard Authorization header, which may increase the risk of access token exposure and replay against protected API endpoints. ### Resolution Upgrade auth0/symfony to version 5.9.0 or greater. ### Acknowledgement Okta would like to thank Alex Yeara for their discovery.
How to fix CVE-2026-50157
To remediate CVE-2026-50157, upgrade the affected package to a fixed version below.
- —upgrade to 5.9.0 or later
Is CVE-2026-50157 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-50157.
Affected packages (1)
- >= 5.0.0-BETA0, < 5.9.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |