Symfony 8.0.13 has been released with several security fixes and bug patches. Security fixes include pinning Mailomat webhook signature algorithm to SHA-256, sanitizing URL attributes in HtmlSanitizer for tags like object, applet, iframe, and img, rejecting percent-encoded BiDi marks in URLs, blocking IPv6 transition forms in IpUtils and NoPrivateNetworkHttpClient, preventing user-supplied failure path exploitation, and fixing dot-segment encoding in generated URLs. Bug fixes cover Console, HttpClient NTLM regression, Cache, Scheduler, SecurityBundle, Process, Mime, Mailer, Translation, AssetMapper, DependencyInjection, and more.
585 Impressions