An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
https://symfony.com/blog/symfony-4-3-8-released
https://symfony.com/blog/cve-2019-18887-use-constant-time-comparison-in-urisigner