CVE-2026-48784
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-172
Error de codificación
Fecha de publicación:
14/07/2026
Última modificación:
15/07/2026
Descripción
*** Pendiente de traducción *** Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.
Impacto
Puntuación base 4.0
5.10
Gravedad 4.0
MEDIA
Puntuación base 3.x
6.10
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* | 5.4.53 (excluyendo) | |
| cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* | 6.0.0 (incluyendo) | 6.4.41 (excluyendo) |
| cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* | 7.0.0 (incluyendo) | 7.4.13 (excluyendo) |
| cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* | 8.0.0 (incluyendo) | 8.0.13 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://github.com/symfony/symfony/commit/4b63c3a3f7af04ecd79c89a594b0b02a01990b1d
- https://github.com/symfony/symfony/releases/tag/v5.4.53
- https://github.com/symfony/symfony/releases/tag/v6.4.41
- https://github.com/symfony/symfony/releases/tag/v7.4.13
- https://github.com/symfony/symfony/security/advisories/GHSA-h5x3-xfc9-m39h



