Skip to content

Symfony Blog

All about Symfony releases, new Symfony features, and other important announcements

Identity Spoofing via Unanchored DN Regex in X509Authenticator
HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite: javascript: URI Survives Sanitization (XSS)
Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
May 20, 2026 #Releases
Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
Sandbox property and method bypass via object-destructuring assignment
XSS in profiler HtmlDumper via unescaped template and profile names
`template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name