Problem/Motivation

https://symfony.com/blog/cve-2025-64500-incorrect-parsing-of-path-info-c...

We are not vulnerable but let's bump minimum versions anyway.

Steps to reproduce

Proposed resolution

Remaining tasks

User interface changes

Introduced terminology

API changes

Data model changes

Release notes snippet

Issue fork drupal-3557393

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

longwave created an issue. See original summary.

longwave changed the visibility of the branch 3557393-update-symfony to hidden.

longwave’s picture

Status: Active » Needs work

ValidateHostnameTest fails on an IPv6 test due to https://github.com/symfony/symfony/pull/62324

alexpott’s picture

Here's the fix for that:

diff --git a/core/tests/Drupal/Tests/Core/DrupalKernel/ValidateHostnameTest.php b/core/tests/Drupal/Tests/Core/DrupalKernel/ValidateHostnameTest.php
index 2c2ad89f4c9..7718914f10f 100644
--- a/core/tests/Drupal/Tests/Core/DrupalKernel/ValidateHostnameTest.php
+++ b/core/tests/Drupal/Tests/Core/DrupalKernel/ValidateHostnameTest.php
@@ -50,7 +50,7 @@ public static function providerTestValidateHostname() {

     // Verifies that using valid IP address for the hostname is allowed.
     $data[] = ['72.21.91.99:80', 'Properly formed HTTP_HOST with IPv4 address valid.', TRUE];
-    $data[] = ['2607:f8b0:4004:803::1002:80', 'Properly formed HTTP_HOST with IPv6 address valid.', TRUE];
+    $data[] = ['[2607:f8b0:4004:803::1002]:80', 'Properly formed HTTP_HOST with IPv6 address valid.', TRUE];

     // Verifies that the IPv6 loopback address is valid.
     $data[] = ['[::1]:80', 'HTTP_HOST containing IPv6 loopback is valid.', TRUE];
xjm’s picture

Edit: Bad references. Getting the good ones and pushing them up now.

xjm’s picture

xjm’s picture

We agreed not to update 11.1.x to Symfony 7.3, so I am going to hide that MR.

xjm changed the visibility of the branch 3557393-update-symfony-11.1.x to hidden.

xjm’s picture

    1)
    Drupal\Tests\file\Functional\DownloadTest::testPrivateFileTransferWithoutPageCache
    Correctly denied access to a file when file_test sets the header to -1.
    Failed asserting that 200 is identical to 403.
xjm’s picture

Status: Needs work » Postponed

Excellent. Postponing.

anmol singh’s picture

  • xjm committed 9aac22d7 on 11.2.x
    Issue #3557393 by longwave, alexpott, xjm, catch: Update Symfony to 7.3....

  • xjm committed cd7fd766 on 10.5.x
    Issue #3557393 by longwave, alexpott, xjm, catch: Update Symfony to 7.3....

  • xjm committed 6eaa56f1 on 10.4.x
    Issue #3557393 by longwave, alexpott, xjm, catch: Update Symfony to 7.3....

  • xjm committed 1eb51be8 on 10.6.x
    Issue #3557393 by longwave, alexpott, xjm, catch: Update Symfony to 7.3....

xjm’s picture

Status: Postponed » Fixed

The 11.2.x, 10.5.x, and 10.4.x MRs were committed as part of today's security releases, and I've committed 10.6.x just now.

We still need an update for 11.x and 11.3.x once Symfony provides an updated beta for Symfony 7.4, but that will come naturally in a followup issue when we update the dependency as part of our normal release process.

@catch, @longwave, and I agreed not to update 11.1.x to 7.3 (as per the 11.1.9 release notes).

Thanks everyone!

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

catch’s picture

This went out with https://www.drupal.org/project/drupal/releases/11.2.8

edit: apparently had this tab open a long time and crossposted.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.