CVE-2026-48760CWE-1007CWE-451

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Medium · published July 14, 2026

CVSS v4.0
5.3
EPSS
0%
Percentile
26.6
In the wild
Unconfirmed
What it is

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstream consumers could decode or display. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.

The record
Technical detail
CVSS v4.0
5.3 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
EPSS
0.00338 · 26.6th percentile
Weaknesses
CWE-1007 · Insufficient Visual Distinction of Homoglyphs Presented to User; CWE-451 · User Interface (UI) Misrepresentation of Critical Information
Published
2026-07-14T19:11Z
EPSS history
Timeline
  • 14 JUL 19:11Z
    Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
    cvelistv5