CVE-2026-48760
MEDIUM SEVERITYVulnerability Description
Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
composer
Product
symfony/html-sanitizer
External References
- https://github.com/symfony/symfony/security/advisories/GHSA-v3wm-qf9p-c549
- https://github.com/symfony/symfony/commit/b21a626fd90f5c12d2db432c629eed3e780ba2f8
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/html-sanitizer/CVE-2026-48760.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2026-48760.yaml
- https://symfony.com/cve-2026-48760
- https://github.com/advisories/GHSA-v3wm-qf9p-c549
Discussion (0)
Add Comment
No comments yet. Be the first!