VYPR

Packagist (Composer) package

symfony/polyfill

pkg:composer/symfony/polyfill

Vulnerabilities (2)

  • CVE-2026-46644MedJul 14, 2026
    affected >= 1.17.1, < 1.38.1fixed 1.38.1

    Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enf

  • CVE-2013-5958Dec 27, 2014
    affected >= 1.0.0, < 1.10.0fixed 1.10.0

    The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKD