Problem/Motivation

I'm using pantheon custom upstream.

When running composer update -W (alternatively composer update-upstream-dependencies), my site updates to core 11.1.9, however when applying updates to an environment, it returns with
pantheon-upstreams/upstream-configuration dev-main requires symfony/http-foundation v7.2.9 -> found symfony/http-foundation[v7.2.9] but these were not loaded, because they are affected by security advisories. To ignore the advisories, add ("PKSA-365x-2zjk-pt47") to the audit "ignore" config. To turn the feature off entirely, you can set "block-insecure" to false in your "audit" config.

It seems that composer update is not addressing security issue, https://symfony.com/blog/cve-2025-64500-incorrect-parsing-of-path-info-c....

Steps to reproduce

I'm running

  • drupal 11.1.9
  • php 8.3
  • composer version 2.7.9

Run composer update --with-all-dependencies with the following settings in composer.json

 "drupal/core-composer-scaffold": "11.1.*",
        "drupal/core-project-message": "11.1.*",
        "drupal/core-recommended": "11.1.*",

After running composer update, this sets my composer.json in upstream-configuration/locked to

 "drupal/core-composer-scaffold": "11.1.9",
        "drupal/core-project-message": "11.1.9",
        "drupal/core-recommended": "11.1.9",
"drupal/core": "11.1.9",
"symfony/console": "v7.2.9",
        "symfony/dependency-injection": "v7.2.9",
        "symfony/deprecation-contracts": "v3.5.1",
        "symfony/error-handler": "v7.2.9",
        "symfony/event-dispatcher": "v7.2.0",
        "symfony/event-dispatcher-contracts": "v3.5.1",
        "symfony/filesystem": "v7.2.9",
        "symfony/finder": "v7.2.9",
        "symfony/http-foundation": "v7.2.9",
        "symfony/http-kernel": "v7.2.9",
        "symfony/mailer": "v7.2.9",
        "symfony/mime": "v7.2.9",
        "symfony/polyfill-ctype": "v1.31.0",
        "symfony/polyfill-iconv": "v1.31.0",
        "symfony/polyfill-intl-grapheme": "v1.31.0",
        "symfony/polyfill-intl-idn": "v1.31.0",
        "symfony/polyfill-intl-normalizer": "v1.31.0",
        "symfony/polyfill-mbstring": "v1.31.0",
        "symfony/polyfill-php81": "v1.33.0",
        "symfony/polyfill-php83": "v1.33.0",
        "symfony/polyfill-php84": "v1.33.0",
        "symfony/process": "v7.2.9",
        "symfony/psr-http-message-bridge": "v7.2.0",
        "symfony/routing": "v7.2.9",
        "symfony/serializer": "v7.2.9",
        "symfony/service-contracts": "v3.5.1",
        "symfony/string": "v7.2.9",
        "symfony/translation-contracts": "v3.5.1",
        "symfony/validator": "v7.2.9",
        "symfony/var-dumper": "v7.2.9",
        "symfony/var-exporter": "v7.2.9",
        "symfony/yaml": "v7.2.9",

Local seems to be fine and running drupal core 11.1.9. However, once I push changes to DEV environment, I am notified of the security issue.

Proposed resolution

I believe that symfony needs to be addressed as well in the latest security update for 11.1 users.

Comments

anthonyroundtree created an issue. See original summary.

anthonyroundtree’s picture

Status: Needs work » Active
quietone’s picture

Just dropping to ask if you have read the drupal 11.1.9 release notes?

anthonyroundtree’s picture

Yes, but the issue is that an environment then prevent updates to 11.1.9 because the security issue is not addressed.

anthonyroundtree’s picture

I've addressed the issue by adding the following to composer.json

"config":
  "audit": {
         "ignore": ["PKSA-365x-2zjk-pt47"]
      }
}
xjm’s picture

Drupal 11.1 is end-of-life in two weeks. It's recommended to update to Drupal 11.2.

Alternately, you can temporarily use drupal/core instead of drupal/core-recommended so that you can unpin from the old version of Symfony.

Note that Drupal is not vulnerable to the issue described in CVE-2025-64500, as mentioned in the release notes, so it's not correct to say it's not "addressing the security issue". For Drupal, there is no security issue. An application will only be potentially vulnerable if it has other code that uses HTTP Foundation directly to expose the vulnerability.

longwave’s picture

Category: Bug report » Support request
Status: Active » Closed (works as designed)

This is a combination of an unfortunate mistake in the 11.1.9 release notes and the recent change in Composer 2.9 where it will refuse to install insecure packages. Other than document the possible fixes, as has already been done above, there is nothing else we can really do here at this stage. The safest solution is to upgrade to Drupal 11.2.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.