Skip to content
RequestGuard Vulnerabilities
Pricing

symfony/html-sanitizer

Provides an object-oriented API to sanitize untrusted HTML input for safe insertion into a document's DOM.

Composer latest 8.1.7 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

8.1.7

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Moderate

5 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

5

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Affected range

ECOSYSTEM: introduced 6.1.0; fixed 6.4.41ECOSYSTEM: introduced 7.0.0; fixed 7.4.13ECOSYSTEM: introduced 8.0.0; fixed 8.0.13>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.41|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.13|>=8.0.0,<8.0.13

Fixed versions: 6.4.41, 7.4.13, 8.0.13

Symfony's HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing

Affected range

ECOSYSTEM: introduced 6.1.0; fixed 6.4.40ECOSYSTEM: introduced 7.0.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12

Fixed versions: 6.4.40, 7.4.12, 8.0.12

Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes

Affected range

ECOSYSTEM: introduced 6.1.0; fixed 6.4.41ECOSYSTEM: introduced 7.0.0; fixed 7.4.13ECOSYSTEM: introduced 8.0.0; fixed 8.0.13>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.41|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.13|>=8.0.0,<8.0.13

Fixed versions: 6.4.41, 7.4.13, 8.0.13

Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification

Affected range

ECOSYSTEM: introduced 6.1.0; fixed 6.4.40ECOSYSTEM: introduced 7.0.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12

Fixed versions: 6.4.40, 7.4.12, 8.0.12

Symfony's HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — `javascript`: URI Survives Sanitization (XSS)

Affected range

ECOSYSTEM: introduced 6.1.0; fixed 6.4.40ECOSYSTEM: introduced 7.0.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12

Fixed versions: 6.4.40, 7.4.12, 8.0.12