<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:51:50 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0653 — De multiples vulnérabilités ont été découvertes dans Symfony. Certaines d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0653</link>
      <description>certfr-2026-avi-0653</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0653</guid>
    </item>
    <item>
      <title>EUVD-2026-339253</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339253</link>
      <description>EUVD-2026-339253</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339253</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48761</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48761</link>
      <description>&lt;p&gt;Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on &amp;lt;object&amp;gt;, &amp;lt;applet&amp;gt;, &amp;lt;iframe&amp;gt;, and &amp;lt;img&amp;gt;, and &amp;lt;meta http-equiv=&amp;#34;refresh&amp;#34;&amp;gt; URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on &amp;lt;object&amp;gt;, &amp;lt;applet&amp;gt;, &amp;lt;iframe&amp;gt;, and &amp;lt;img&amp;gt;, and &amp;lt;meta http-equiv=&amp;#34;refresh&amp;#34;&amp;gt; URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48761</guid>
    </item>
    <item>
      <title>GHSA-x5qj-865h-mgvm — Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x5qj-865h-mgvm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: symfony/html-sanitizer, Packagist: symfony/symfony&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;`Symfony\Component\HtmlSanitizer\Visitor\AttributeSanitizer\UrlAttributeSanitizer::getSupportedAttributes()` enumerates the attribute names whose values are scrubbed through `UrlSanitizer::sanitize()` (scheme and host allow-lists, `javascript:` rejection, BiDi check, etc.). The list is `[&amp;#39;src&amp;#39;, &amp;#39;href&amp;#39;, &amp;#39;lowsrc&amp;#39;, &amp;#39;background&amp;#39;, &amp;#39;ping&amp;#39;, &amp;#39;action&amp;#39;, &amp;#39;formaction&amp;#39;, &amp;#39;poster&amp;#39;, &amp;#39;cite&amp;#39;]`. Other URL-bearing attributes are absent: `&amp;lt;object data=…&amp;gt;`, `&amp;lt;applet codebase=…&amp;gt;`, `&amp;lt;applet archive=…&amp;gt;` and `&amp;lt;object archive=…&amp;gt;`, `&amp;lt;iframe longdesc=…&amp;gt;` and `&amp;lt;img longdesc=…&amp;gt;`. When an integrator opts these elements/attributes in via `allowElement(&amp;#39;object&amp;#39;, [&amp;#39;data&amp;#39;])`, `allowElement(&amp;#39;applet&amp;#39;, [&amp;#39;codebase&amp;#39;])`, etc., or via `allowAttribute()`, no URL sanitization runs: `data=&amp;#34;javascript:alert(1)&amp;#34;` and similar payloads ship through unchanged into the output, enabling stored XSS.&lt;/p&gt;
&lt;p&gt;`&amp;lt;meta http-equiv=&amp;#34;refresh&amp;#34; content=&amp;#34;0; url=…&amp;#34;&amp;gt;` is the same class of bug routed differently: the URL is embedded inside a multi-field `content` attribute that the per-attribute sanitizer cannot detect from the attribute name alone. Integrators who enable `&amp;lt;meta&amp;gt;` with the `content` attribute (e.g. via `allowStaticElements()`) see `content=&amp;#34;0; url=javascript:alert(1)&amp;#34;` pass through, producing a refresh-driven navigation to a `javascript:` URL.&lt;/p&gt;
&lt;p&gt;Default configurations are not affected: `&amp;lt;object&amp;gt;`, `&amp;lt;applet&amp;gt;` and `&amp;lt;iframe&amp;gt;` are not in `W3CReference::BODY_ELEMENTS` and `&amp;lt;meta&amp;gt;` requires an explicit opt-in to `&amp;lt;head&amp;gt;`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: symfony/html-sanitizer, Packagist: symfony/symfony&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;`Symfony\Component\HtmlSanitizer\Visitor\AttributeSanitizer\UrlAttributeSanitizer::getSupportedAttributes()` enumerates the attribute names whose values are scrubbed through `UrlSanitizer::sanitize()` (scheme and host allow-lists, `javascript:` rejection, BiDi check, etc.). The list is `[&amp;#39;src&amp;#39;, &amp;#39;href&amp;#39;, &amp;#39;lowsrc&amp;#39;, &amp;#39;background&amp;#39;, &amp;#39;ping&amp;#39;, &amp;#39;action&amp;#39;, &amp;#39;formaction&amp;#39;, &amp;#39;poster&amp;#39;, &amp;#39;cite&amp;#39;]`. Other URL-bearing attributes are absent: `&amp;lt;object data=…&amp;gt;`, `&amp;lt;applet codebase=…&amp;gt;`, `&amp;lt;applet archive=…&amp;gt;` and `&amp;lt;object archive=…&amp;gt;`, `&amp;lt;iframe longdesc=…&amp;gt;` and `&amp;lt;img longdesc=…&amp;gt;`. When an integrator opts these elements/attributes in via `allowElement(&amp;#39;object&amp;#39;, [&amp;#39;data&amp;#39;])`, `allowElement(&amp;#39;applet&amp;#39;, [&amp;#39;codebase&amp;#39;])`, etc., or via `allowAttribute()`, no URL sanitization runs: `data=&amp;#34;javascript:alert(1)&amp;#34;` and similar payloads ship through unchanged into the output, enabling stored XSS.&lt;/p&gt;
&lt;p&gt;`&amp;lt;meta http-equiv=&amp;#34;refresh&amp;#34; content=&amp;#34;0; url=…&amp;#34;&amp;gt;` is the same class of bug routed differently: the URL is embedded inside a multi-field `content` attribute that the per-attribute sanitizer cannot detect from the attribute name alone. Integrators who enable `&amp;lt;meta&amp;gt;` with the `content` attribute (e.g. via `allowStaticElements()`) see `content=&amp;#34;0; url=javascript:alert(1)&amp;#34;` pass through, producing a refresh-driven navigation to a `javascript:` URL.&lt;/p&gt;
&lt;p&gt;Default configurations are not affected: `&amp;lt;object&amp;gt;`, `&amp;lt;applet&amp;gt;` and `&amp;lt;iframe&amp;gt;` are not in `W3CReference::BODY_ELEMENTS` and `&amp;lt;meta&amp;gt;` requires an explicit opt-in to `&amp;lt;head&amp;gt;`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x5qj-865h-mgvm</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48761</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48761</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: symfony, Ubuntu:Pro:18.04:LTS: symfony, Ubuntu:Pro:20.04:LTS: symfony, Ubuntu:Pro:22.04:LTS: symfony, Ubuntu:Pro:24.04:LTS: symfony, Ubuntu:25.10: symfony, Ubuntu:26.04:LTS: symfony&lt;/p&gt;
&lt;p&gt;Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on &amp;lt;object&amp;gt;, &amp;lt;applet&amp;gt;, &amp;lt;iframe&amp;gt;, and &amp;lt;img&amp;gt;, and &amp;lt;meta http-equiv=&amp;#34;refresh&amp;#34;&amp;gt; URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: symfony, Ubuntu:Pro:18.04:LTS: symfony, Ubuntu:Pro:20.04:LTS: symfony, Ubuntu:Pro:22.04:LTS: symfony, Ubuntu:Pro:24.04:LTS: symfony, Ubuntu:25.10: symfony, Ubuntu:26.04:LTS: symfony&lt;/p&gt;
&lt;p&gt;Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on &amp;lt;object&amp;gt;, &amp;lt;applet&amp;gt;, &amp;lt;iframe&amp;gt;, and &amp;lt;img&amp;gt;, and &amp;lt;meta http-equiv=&amp;#34;refresh&amp;#34;&amp;gt; URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48761</guid>
    </item>
  </channel>
</rss>
