<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:49:20.257609+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0653</id>
    <title>certfr-2026-avi-0653 — De multiples vulnérabilités ont été découvertes dans Symfony. Certaines d'entre elles permettent à un attaquant de prov…</title>
    <updated>2026-10-02T17:49:20.339143+00:00</updated>
    <content>certfr-2026-avi-0653</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0653"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339253</id>
    <title>EUVD-2026-339253</title>
    <updated>2026-10-02T17:49:20.339187+00:00</updated>
    <content>EUVD-2026-339253</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339253"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48761</id>
    <title>fkie_cve-2026-48761</title>
    <updated>2026-10-02T17:49:20.339202+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on &lt;object&gt;, &lt;applet&gt;, &lt;iframe&gt;, and &lt;img&gt;, and &lt;meta http-equiv="refresh"&gt; URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48761"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x5qj-865h-mgvm</id>
    <title>GHSA-x5qj-865h-mgvm — Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes</title>
    <updated>2026-10-02T17:49:20.339260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: symfony/html-sanitizer, Packagist: symfony/symfony</p>
<p>### Description</p>
<p>`Symfony\Component\HtmlSanitizer\Visitor\AttributeSanitizer\UrlAttributeSanitizer::getSupportedAttributes()` enumerates the attribute names whose values are scrubbed through `UrlSanitizer::sanitize()` (scheme and host allow-lists, `javascript:` rejection, BiDi check, etc.). The list is `['src', 'href', 'lowsrc', 'background', 'ping', 'action', 'formaction', 'poster', 'cite']`. Other URL-bearing attributes are absent: `&lt;object data=…&gt;`, `&lt;applet codebase=…&gt;`, `&lt;applet archive=…&gt;` and `&lt;object archive=…&gt;`, `&lt;iframe longdesc=…&gt;` and `&lt;img longdesc=…&gt;`. When an integrator opts these elements/attributes in via `allowElement('object', ['data'])`, `allowElement('applet', ['codebase'])`, etc., or via `allowAttribute()`, no URL sanitization runs: `data="javascript:alert(1)"` and similar payloads ship through unchanged into the output, enabling stored XSS.</p>
<p>`&lt;meta http-equiv="refresh" content="0; url=…"&gt;` is the same class of bug routed differently: the URL is embedded inside a multi-field `content` attribute that the per-attribute sanitizer cannot detect from the attribute name alone. Integrators who enable `&lt;meta&gt;` with the `content` attribute (e.g. via `allowStaticElements()`) see `content="0; url=javascript:alert(1)"` pass through, producing a refresh-driven navigation to a `javascript:` URL.</p>
<p>Default configurations are not affected: `&lt;object&gt;`, `&lt;applet&gt;` and `&lt;iframe&gt;` are not in `W3CReference::BODY_ELEMENTS` and `&lt;meta&gt;` requires an explicit opt-in to `&lt;head&gt;`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x5qj-865h-mgvm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48761</id>
    <title>UBUNTU-CVE-2026-48761</title>
    <updated>2026-10-02T17:49:20.339318+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: symfony, Ubuntu:Pro:18.04:LTS: symfony, Ubuntu:Pro:20.04:LTS: symfony, Ubuntu:Pro:22.04:LTS: symfony, Ubuntu:Pro:24.04:LTS: symfony, Ubuntu:25.10: symfony, Ubuntu:26.04:LTS: symfony</p>
<p>Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on &lt;object&gt;, &lt;applet&gt;, &lt;iframe&gt;, and &lt;img&gt;, and &lt;meta http-equiv="refresh"&gt; URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48761"/>
  </entry>
</feed>
