Skip to content

Symfony Blog

All about Symfony releases, new Symfony features, and other important announcements

HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and Misclassification
YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix
XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address
Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
May 20, 2026 #Releases 🚀 1
Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
`template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments