CVE-2026-48784
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
- EPSS probability
- 0.35%
- CWE
- CWE-172, CWE-601
- Published
- 2026-07-14
- Last modified
- 2026-07-15
Affected products
- symfony symfony
- symfony symfony
- symfony symfony
- symfony symfony
- symfony routing
- symfony routing
- symfony routing
- symfony routing
Weakness type
Related vulnerabilities
- CVE-2026-42926 — NGINX ngx_http_proxy_v2_module vulnerability
- CVE-2025-27110 — Libmodsecurity3 has possible bypass of encoded HTML entities
- CVE-2024-48909 — SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not
- CVE-2021-33604 — Reflected cross-site scripting in development mode handler in Vaadin 14, 15-19
- CVE-2019-12677 — Cisco Adaptive Security Appliance Software SSL VPN Denial of Service Vulnerability
- CVE-2019-10153 — A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in...
- CVE-2019-10160 — A security regression of CVE-2019-9636 was discovered in python since commit...