symfony/html-sanitizer is vulnerable to Interpretation Conflict
61
Medium Risk
allowLinkHosts() and allowMediaHosts() rely on URL parsing that differs from browser URL handling. Backslashes, unusual slash counts, and area element handling can make a URL pass server-side allowlists while navigating elsewhere in the browser. Pre-fix sanitized content can smuggle off-allowlist link or media targets. The fix rejects parser-differential URL forms and applies link policy to area elements.
You are affected if you are using a version that falls within the vulnerable range.
symfony/html-sanitizer is vulnerable to Interpretation Conflict in versions 6.1.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.
Upgrade the symfony/html-sanitizer and/or symfony/symfony library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant