CVE-2026-48760CWE-1007CWE-451
Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
Medium · published July 14, 2026
What it is
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstream consumers could decode or display. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.
The record
Technical detail
- CVSS v4.0
- 5.3 · MEDIUM
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
- EPSS
- 0.00338 · 26.6th percentile
- Weaknesses
- CWE-1007 · Insufficient Visual Distinction of Homoglyphs Presented to User; CWE-451 · User Interface (UI) Misrepresentation of Critical Information
- Published
- 2026-07-14T19:11Z
EPSS history
Timeline