Skip to content

Symfony Blog

All about Symfony releases, new Symfony features, and other important announcements

Join Sean Mackay at SymfonyDay Montreal as he breaks down the key Symfony features (Doctrine, Messenger, Events) that transformed Pimcore into a robust, update-friendly platform
May 27, 2026 #Conferences
May 27, 2026 #Releases
May 27, 2026 #Releases
HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on object, applet, iframe, img and the URL Inside meta http-equiv="refresh" content
Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
UrlGenerator Dot-Segment Encoding Skips Every Other Chained ../ or ./: Generated URL Collapses Off-Route Under RFC 3986 Normalization
May 27, 2026 #Security Advisories #Symfony ❤️ 1
IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes
May 27, 2026 #Releases ❤️ 2