Problem/Motivation
I'm using pantheon custom upstream.
When running composer update -W (alternatively composer update-upstream-dependencies), my site updates to core 11.1.9, however when applying updates to an environment, it returns with
pantheon-upstreams/upstream-configuration dev-main requires symfony/http-foundation v7.2.9 -> found symfony/http-foundation[v7.2.9] but these were not loaded, because they are affected by security advisories. To ignore the advisories, add ("PKSA-365x-2zjk-pt47") to the audit "ignore" config. To turn the feature off entirely, you can set "block-insecure" to false in your "audit" config.
It seems that composer update is not addressing security issue, https://symfony.com/blog/cve-2025-64500-incorrect-parsing-of-path-info-c....
Steps to reproduce
I'm running
- drupal 11.1.9
- php 8.3
- composer version 2.7.9
Run composer update --with-all-dependencies with the following settings in composer.json
"drupal/core-composer-scaffold": "11.1.*",
"drupal/core-project-message": "11.1.*",
"drupal/core-recommended": "11.1.*",After running composer update, this sets my composer.json in upstream-configuration/locked to
"drupal/core-composer-scaffold": "11.1.9",
"drupal/core-project-message": "11.1.9",
"drupal/core-recommended": "11.1.9",
"drupal/core": "11.1.9",
"symfony/console": "v7.2.9",
"symfony/dependency-injection": "v7.2.9",
"symfony/deprecation-contracts": "v3.5.1",
"symfony/error-handler": "v7.2.9",
"symfony/event-dispatcher": "v7.2.0",
"symfony/event-dispatcher-contracts": "v3.5.1",
"symfony/filesystem": "v7.2.9",
"symfony/finder": "v7.2.9",
"symfony/http-foundation": "v7.2.9",
"symfony/http-kernel": "v7.2.9",
"symfony/mailer": "v7.2.9",
"symfony/mime": "v7.2.9",
"symfony/polyfill-ctype": "v1.31.0",
"symfony/polyfill-iconv": "v1.31.0",
"symfony/polyfill-intl-grapheme": "v1.31.0",
"symfony/polyfill-intl-idn": "v1.31.0",
"symfony/polyfill-intl-normalizer": "v1.31.0",
"symfony/polyfill-mbstring": "v1.31.0",
"symfony/polyfill-php81": "v1.33.0",
"symfony/polyfill-php83": "v1.33.0",
"symfony/polyfill-php84": "v1.33.0",
"symfony/process": "v7.2.9",
"symfony/psr-http-message-bridge": "v7.2.0",
"symfony/routing": "v7.2.9",
"symfony/serializer": "v7.2.9",
"symfony/service-contracts": "v3.5.1",
"symfony/string": "v7.2.9",
"symfony/translation-contracts": "v3.5.1",
"symfony/validator": "v7.2.9",
"symfony/var-dumper": "v7.2.9",
"symfony/var-exporter": "v7.2.9",
"symfony/yaml": "v7.2.9",Local seems to be fine and running drupal core 11.1.9. However, once I push changes to DEV environment, I am notified of the security issue.
Proposed resolution
I believe that symfony needs to be addressed as well in the latest security update for 11.1 users.
Comments
Comment #2
anthonyroundtree commentedComment #3
quietone commentedJust dropping to ask if you have read the drupal 11.1.9 release notes?
Comment #4
anthonyroundtree commentedYes, but the issue is that an environment then prevent updates to 11.1.9 because the security issue is not addressed.
Comment #5
anthonyroundtree commentedI've addressed the issue by adding the following to composer.json
Comment #6
xjmDrupal 11.1 is end-of-life in two weeks. It's recommended to update to Drupal 11.2.
Alternately, you can temporarily use
drupal/coreinstead ofdrupal/core-recommendedso that you can unpin from the old version of Symfony.Note that Drupal is not vulnerable to the issue described in CVE-2025-64500, as mentioned in the release notes, so it's not correct to say it's not "addressing the security issue". For Drupal, there is no security issue. An application will only be potentially vulnerable if it has other code that uses HTTP Foundation directly to expose the vulnerability.
Comment #7
longwaveThis is a combination of an unfortunate mistake in the 11.1.9 release notes and the recent change in Composer 2.9 where it will refuse to install insecure packages. Other than document the possible fixes, as has already been done above, there is nothing else we can really do here at this stage. The safest solution is to upgrade to Drupal 11.2.