Threat Advisory

API Platform Core Flaw Lets Attackers Denormalize Relation Resources

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability identified as CVE-2026-54164 with a CVSS score of 6.5, affects API Platform Core versions prior to 4.1.30, between 4.2.0 and 4.2.26, and between 4.3.0 and 4.3.12. The flaw is related to type confusion where a resource of an unintended type can be silently assigned to a relation property, potentially allowing an attacker who can submit write requests to supply a relation IRI pointing to a resource of a different type than the relation's declared class. This could corrupt invariants and feed downstream logic that assumes the declared type, leading to business impact due to potential data corruption or security breaches. The vulnerability exists because the API Platform serializer's AbstractItemNormalizer does not validate the resource type returned when resolving relation IRIs.

RECOMMENDATION:

We recommend you to update api-platform/core to version 4.1.30, 4.2.26, or 4.3.12.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability identified as CVE-2026-54164 with a CVSS score of 6.5, affects API Platform Core versions prior to 4.1.30, between 4.2.0 and 4.2.26, and between 4.3.0 and 4.3.12. The flaw is related to type confusion where a resource of an unintended type can be silently assigned to a relation property, potentially allowing an attacker who can submit write requests to supply a relation IRI pointing to a resource of a different type than the relation's declared class. This could corrupt invariants and feed downstream logic that assumes the declared type, leading to business impact due to potential data corruption or security breaches. The vulnerability exists because the API Platform serializer's AbstractItemNormalizer does not validate the resource type returned when resolving relation IRIs.

RECOMMENDATION:

We recommend you to update api-platform/core to version 4.1.30, 4.2.26, or 4.3.12.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu