CVE-2026-45066 | Symfony up to 6.4.39/7.4.11/8.0.11 HtmlSanitizer allowLinkHosts/allowMediaHosts Remote Code Execution
A vulnerability classified as critical was found in Symfony up to 6.4.39/7.4.11/8.0.11. Affected by this issue is the function allowLinkHosts/allowMediaHosts of the component HtmlSanitizer. The manipulation results in Remote Code Execution.
This vulnerability was named CVE-2026-45066. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More