Skip to content

Symfony Blog

All about Symfony releases, new Symfony features, and other important announcements

HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and Misclassification
May 20, 2026 #Releases 🚀 1
Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
Arbitrary PHP code execution via `_self.(
Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments
PHP code injection via `{% use %}` template name
HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
`{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
Sandbox property and method bypass via object-destructuring assignment
XSS in profiler HtmlDumper via unescaped template and profile names