CVE-2026-45064CWE-1007CWE-451

Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing

Low · published July 14, 2026

CVSS v4.0
2.3
EPSS
0%
Percentile
26.6
In the wild
Unconfirmed
What it is

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href and src attributes, allowing sanitized content to display a link destination that visually differs from the actual destination and enabling phishing-style visual spoofing. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

The record
Technical detail
CVSS v4.0
2.3 · LOW
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
EPSS
0.00338 · 26.6th percentile
Weaknesses
CWE-1007 · Insufficient Visual Distinction of Homoglyphs Presented to User; CWE-451 · User Interface (UI) Misrepresentation of Critical Information
Published
2026-07-14T18:35Z
EPSS history
Timeline
  • 14 JUL 18:35Z
    Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
    cvelistv5