Symfony 8.0.13 has been released with several security fixes and bug patches. Security fixes include pinning Mailomat webhook signature algorithm to SHA-256, sanitizing URL attributes in HtmlSanitizer for tags like object, applet, iframe, and img, rejecting percent-encoded BiDi marks in URLs, blocking IPv6 transition forms in IpUtils and NoPrivateNetworkHttpClient, preventing user-supplied failure path exploitation, and fixing dot-segment encoding in generated URLs. Bug fixes cover Console, HttpClient NTLM regression, Cache, Scheduler, SecurityBundle, Process, Mime, Mailer, Translation, AssetMapper, DependencyInjection, and more.

3m read timeFrom symfony.com
Post cover image
584 Impressions