MEDIUMPackagist
GHSA-72xp-p242-47p9· CVE-2026-45065Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
Modified: 9/10/2026
package
pkg:packagist/symfony/routing
Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
Modified: 9/10/2026
Symfony Allows URI Restrictions Bypass Via Double-Encoded String
Modified: 12/3/2024
Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
Modified: 9/10/2026
Symfony XXE security vulnerability
Modified: 12/4/2024