Skip to content

Symfony Blog

All about Symfony releases, new Symfony features, and other important announcements

Identity Spoofing via Unanchored DN Regex in X509Authenticator
HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims
XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
Stored XSS in WebProfiler CodeExtension::fileExcerpt(): Unescaped Non-PHP File Rendering
SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix
Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]
YAML Parser Stack Exhaustion via Unbounded Recursion in Nested Blocks, Sequences, and Mappings
HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite: javascript: URI Survives Sanitization (XSS)