Junglewise Threat Intelligence

CVE-2026-45066: Symfony HtmlSanitizer URL allowlist bypass in URL parser

CVE-2026-45066 · Severity: medium · CVSS 0 · Published 2026-07-14

Technologies: Symfony HtmlSanitizer. Vendors: Symfony.

Executive brief

A vulnerability in the Symfony PHP framework's HTML sanitization component could allow malicious links to bypass security filters. This component is used by developers to clean user-provided content and prevent security risks like phishing or unauthorized redirects. If exploited, an attacker could trick users into visiting malicious websites that were supposed to be blocked by the application's safety rules.

Technical details

A vulnerability exists in Symfony's HtmlSanitizer component where URL allowlists can be bypassed. The root cause is twofold: first, UrlSanitizer::parse() follows RFC 3986 while modern browsers follow the WHATWG URL spec, creating a parser differential that allows specially crafted URLs to bypass host checks. Second, the <area href> attribute was incorrectly validated against the media policy instead of the link policy. An attacker can exploit this by providing malicious HTML content that includes links to unauthorized domains. The issue is resolved in versions 6.4.40, 7.4.12, and 8.0.12.

Affected products

  • Symfony symfony/symfony >= 6.1.0-BETA1, < 6.4.40; >= 7.0.0-BETA1, < 7.4.12; >= 8.0.0-BETA1, < 8.0.12
  • Symfony symfony/html-sanitizer >= 6.1.0-BETA1, < 6.4.40; >= 7.0.0-BETA1, < 7.4.12; >= 8.0.0-BETA1, < 8.0.12

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-05-20: patched

References

Related threats