CVE-2026-48760: Sensiolabs Symfony
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstream consumers could decode or display. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.
Affected products
- Sensiolabs Symfony: from 6.1.0, before 6.4.41 (fixed in 6.4.41); from 7.0.0, before 7.4.13 (fixed in 7.4.13); from 8.0.0, before 8.0.13 (fixed in 8.0.13)
Published 2026-07-14. Last modified 2026-07-15.