cbcvebase.
CVE-2026-45066
published 2026-07-14

CVE-2026-45066: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12…

PriorityP433medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.29%
21.0th percentile
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization can allow off-allowlist URLs through allowLinkHosts() or allowMediaHosts() because UrlSanitizer::parse() follows RFC 3986 while browsers follow WHATWG URL parsing, and because is checked against the media policy rather than the link policy. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

Affected

15 ranges
VendorProductVersion rangeFixed in
sensiolabssymfony>= 6.1.0 < 6.4.406.4.40
sensiolabssymfony>= 7.0.0 < 7.4.127.4.12
sensiolabssymfony>= 8.0.0 < 8.0.128.0.12
symfonyhtml-sanitizer
symfonyhtml-sanitizer
symfonyhtml-sanitizer
symfonyhtml-sanitizer>= 6.1.0 < 6.4.406.4.40
symfonyhtml-sanitizer>= 7.0.0 < 7.4.127.4.12
symfonyhtml-sanitizer>= 8.0.0 < 8.0.128.0.12
symfonysymfony
symfonysymfony
symfonysymfony
symfonysymfony>= 6.1.0 < 6.4.406.4.40
symfonysymfony>= 7.0.0 < 7.4.127.4.12
symfonysymfony>= 8.0.0 < 8.0.128.0.12

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.