VYPR

Packagist (Composer) package

symfony/html-sanitizer

pkg:composer/symfony/html-sanitizer

Vulnerabilities (2)

  • CVE-2026-45064MedJul 14, 2026
    affected >= 6.1.0, < 6.4.40fixed 6.4.40

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href and src attributes,

  • CVE-2026-45066MedJul 14, 2026
    affected >= 6.1.0, < 6.4.40fixed 6.4.40

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization can allow off-allowlist URLs through allowLinkHosts() or allowMediaHosts() because UrlSanitizer::par