CVE-2026-50157: CWE-598: Use of GET Request Method With Sensitive Query Strings in auth0 symfony
Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as the Authorization header for protected HTTP routes. Query-string tokens can be recorded in server logs, browser history, or referrer data and then replayed against protected API endpoints. This issue is fixed in version 5.9.0.
AI Analysis
Technical Summary
The Auth0 Symfony SDK for Authentication and Management APIs versions >=5.0.0-BETA0 and <5.9.0 include a security flaw in the Authorizer security authenticator. Specifically, the authenticate() and supports() methods accept OAuth 2.0 bearer access tokens from the token URL query parameter in addition to the Authorization header. Using GET requests with sensitive tokens in query strings can lead to token exposure through logs, browser history, or referrer headers, increasing the risk of token replay attacks. This vulnerability is tracked as CVE-2026-50157 and is classified under CWE-598 (Use of GET Request Method With Sensitive Query Strings). The vulnerability has a CVSS 3.1 base score of 6.5 (medium severity) and is fixed in version 5.9.0.
Potential Impact
The vulnerability allows sensitive OAuth 2.0 bearer tokens to be exposed in URL query parameters, which can be recorded in server logs, browser history, or referrer data. This exposure can lead to unauthorized replay of tokens against protected API endpoints, potentially allowing unauthorized access. The CVSS score of 6.5 reflects a medium severity impact with high confidentiality impact but no impact on integrity or availability.
Mitigation Recommendations
Upgrade Auth0 Symfony to version 5.9.0 or later, where this issue is fixed. Avoid using OAuth 2.0 bearer tokens in URL query parameters and instead use the Authorization header for token transmission. There is no indication that temporary mitigations or workarounds are provided by the vendor.
CVE-2026-50157: CWE-598: Use of GET Request Method With Sensitive Query Strings in auth0 symfony
Description
Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as the Authorization header for protected HTTP routes. Query-string tokens can be recorded in server logs, browser history, or referrer data and then replayed against protected API endpoints. This issue is fixed in version 5.9.0.
CVSS v3.1
Score 6.5medium
Affected software
auth0
symfony
pkg:github/auth0/symfonyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Auth0 Symfony SDK for Authentication and Management APIs versions >=5.0.0-BETA0 and <5.9.0 include a security flaw in the Authorizer security authenticator. Specifically, the authenticate() and supports() methods accept OAuth 2.0 bearer access tokens from the token URL query parameter in addition to the Authorization header. Using GET requests with sensitive tokens in query strings can lead to token exposure through logs, browser history, or referrer headers, increasing the risk of token replay attacks. This vulnerability is tracked as CVE-2026-50157 and is classified under CWE-598 (Use of GET Request Method With Sensitive Query Strings). The vulnerability has a CVSS 3.1 base score of 6.5 (medium severity) and is fixed in version 5.9.0.
Potential Impact
The vulnerability allows sensitive OAuth 2.0 bearer tokens to be exposed in URL query parameters, which can be recorded in server logs, browser history, or referrer data. This exposure can lead to unauthorized replay of tokens against protected API endpoints, potentially allowing unauthorized access. The CVSS score of 6.5 reflects a medium severity impact with high confidentiality impact but no impact on integrity or availability.
Mitigation Recommendations
Upgrade Auth0 Symfony to version 5.9.0 or later, where this issue is fixed. Avoid using OAuth 2.0 bearer tokens in URL query parameters and instead use the Authorization header for token transmission. There is no indication that temporary mitigations or workarounds are provided by the vendor.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-03T20:54:20.432Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa8300255bf5e2cf5600a6a
Added to database: 09/14/2026, 17:33:54 UTC
Last enriched: 09/14/2026, 17:47:04 UTC
Last updated: 09/15/2026, 03:19:53 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.