OktaOKTA-04640PF
Insufficient Entropy in Cookie Encryption in Auth0 Symfony SDK CVE-2026-34236 - Apr 1...
UnratedCVE-2026-34236 · Published Apr 1, 2026
In applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and forging session cookies. To remediate, upgrade Auth0/symfony-auth0 to version 5.8.0 or greater.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 10 | Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK CVE-2026-50157 - Jun... | Unrated | No fix yet |
| May 6 | Improper Permission Checking in Auth0.js SDK CVE-2026-42280 - May 6, 2026 | Unrated | No fix yet |
| Apr 17 | Improper Proxy Cache Lookup in the Auth0 Next.js SDK CVE-2026-40155 - Apr 17, 2026 | Unrated | No fix yet |
| Dec 102025 | Improper Validation of Query Parameters in Auth0 Next.js SDK CVE-2025-67716 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Improper Request Caching Lookup in the Auth0 Next.js SDK CVE-2025-67490 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Improper Memory Cleanup in the Okta Java SDK CVE-2025-66033 - Dec 10, 2025 | Unrated | No fix yet |