AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-11386

MEDIUM · CVSS 5.9 EPSS 1.61%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-06-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-11386
Severity
MEDIUM
CVSS
5.9
EPSS
1.61%

Original NVD Description

An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources.