PKSA-t5z9-jvfg-zqhb Security Advisory
-
[MEDIUM] CVE-2026-45064: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
PKSA-t5z9-jvfg-zqhb CVE-2026-45064 GHSA-h5vq-qfcg-4m6p
Affected package: symfony/symfony
Affected version: >=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
Reported by:
GitHub, FriendsOfPHP/security-advisories