Search CVE reports


Toggle filters

1 – 10 of 91 results


CVE-2026-46644

Medium priority
Needs evaluation

Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to...

1 affected package

php-symfony-polyfill

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-symfony-polyfill Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-48784

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-48761

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-48760

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-48747

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-48736

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-48489

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler honored the request-supplied _failure_path...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-47212

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the configured webhook secret but ignored the...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45071

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(),...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45068

Medium priority
Needs evaluation

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages