Symfony 7.4.13 has been released with several security fixes and bug patches. Security fixes include pinning Mailomat webhook signature algorithm to SHA-256, sanitizing URL attributes in HtmlSanitizer for tags like object, applet, iframe, and img, rejecting percent-encoded BiDi marks in URLs, blocking IPv6 transition forms in IpUtils and NoPrivateNetworkHttpClient, fixing failure path handling in Security, and correcting dot-segment encoding in generated URLs. Bug fixes cover areas including Console, HttpClient NTLM regression, Cache, Scheduler, SecurityBundle, Process, Mime, Mailer, Yaml, Translation, AssetMapper, DependencyInjection, and HttpKernel.
846 Impressions