CVE-2026-48784
MEDIUMDescription
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
Is your site exposed to CVE-2026-48784?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sensiolabs | symfony |
| sensiolabs | symfony |
| sensiolabs | symfony |
| sensiolabs | symfony |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-48784? +
How severe is CVE-2026-48784? +
What products are affected by CVE-2026-48784? +
How do I check if I'm vulnerable to CVE-2026-48784? +
Related Vulnerabilities
Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking …
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements …
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an …
SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior …
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until …
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, …