CVE-2026-49858 | api-platform core/hal/json-api up to 4.1.28/4.2.24/4.3.7 cache_key cache containing sensitive information (GHSA-pjhx-3c3w-9v23)
A vulnerability was found in api-platform core, hal and json-api up to 4.1.28/4.2.24/4.3.7 and classified as problematic. This affects an unknown function. Such manipulation of the argument cache_key leads to use of cache containing sensitive information.
This vulnerability is referenced as CVE-2026-49858. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More