Junglewise Threat Intelligence

CVE-2026-46644: Symfony Polyfill improper validation of Punycode labels in Intl-Idn

CVE-2026-46644 · Severity: medium · CVSS 4 · Published 2026-07-14

Vendors: Symfony, Packagist.

Executive brief

A vulnerability exists in a Symfony component used to handle internationalized domain names (IDNs) in PHP applications. The software incorrectly treats certain malformed web addresses as valid, which can allow attackers to bypass security filters or trick servers into making unauthorized requests (SSRF). This could lead to unauthorized access to internal systems or the bypassing of domain-based blocklists.

Technical details

The symfony/polyfill-intl-idn package fails to enforce the UTS #46 revision 33 requirement in its Idn::process() method. Specifically, it does not verify that decoded ACE (xn--) labels contain at least one non-ASCII code point. This allows labels with empty or ASCII-only Punycode payloads to be accepted rather than rejected with an IDNA_ERROR_INVALID_ACE_LABEL. An attacker can exploit this inconsistency to cause originally unequal domain names to be treated as equivalent. This can result in blacklist bypassing, inconsistent URL parsing, and Server-Side Request Forgery (SSRF) in applications that rely on the polyfill for hostname canonicalization or comparison. The issue is fixed in version 1.38.1.

Affected products

  • Symfony polyfill-intl-idn >= 1.17.1, < 1.38.1
  • Symfony polyfill >= 1.17.1, < 1.38.1

Timeline

  • 2026-05-26: patched: Version 1.38.1 released
  • 2026-05-26: advisory: GitHub Security Advisory GHSA-2xf4-cg6j-vhgq published
  • 2026-07-14: disclosed: CVE-2026-46644 published to NVD

References