Skip to content
OktaOKTA-02JA0JI

Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK CVE-2026-50157 - Jun...

UnratedCVE-2026-50157 · Published Jun 10, 2026

Applications built with the Auth0 Symphony SDK, using the Authorizer security authenticator to protect HTTP routes may accept OAuth 2.0 bearer access tokens provided through a URL query parameter, in addition to the standard Authorization header, which may increase the risk of access token exposure and replay against protected API endpoints. To remediate, upgrade auth0/symfony to version 5.9.0 or greater.

Okta advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Okta advisories

All Okta
Advisory
Okta Access Gateway: code execution
Medium6.6Sep 8
Okta Access Gateway: code injection
Medium6.6Sep 8
Okta Privileged Access Client: command injection
Medium5.3Aug 25
Improper Permission Checking in Auth0.js SDK CVE-2026-42280 - May 6, 2026
UnratedMay 6
Improper Proxy Cache Lookup in the Auth0 Next.js SDK CVE-2026-40155 - Apr 17, 2026
UnratedApr 17
Insufficient Entropy in Cookie Encryption in Auth0 Symfony SDK CVE-2026-34236 - Apr 1...
UnratedApr 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.