-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 27 May 2026 12:03:54 +0200
Source: symfony
Architecture: source
Version: 7.4.13+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian PHP PEAR Maintainers <pkg-php-pear@lists.alioth.debian.org>
Changed-By: David Prévot <taffit@debian.org>
Changes:
symfony (7.4.13+dfsg-1) unstable; urgency=medium
.
[ Fabien Potencier ]
* Update VERSION for 7.4.13
.
[ Nicolas Grekas ]
* [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient
[CVE-2026-48736]
* [HttpFoundation] Block IPv6 transition forms in IpUtils::PRIVATE_SUBNETS
[CVE-2026-48736]
* [Mailer] Pin Mailomat webhook signature algorithm to SHA-256
[CVE-2026-48747]
* [HtmlSanitizer] Reject percent-encoded BiDi marks and Unicode whitespace
in URLs [CVE-2026-48760]
* [HtmlSanitizer] Sanitize URL attributes on <object>, <applet>, <iframe>,
<img>, and the URL inside <meta http-equiv="refresh"> content
[CVE-2026-48761]
* [Routing] Fix dot-segment encoding for chained "../" and "./" in generated
URLs [CVE-2026-48784]
* [Security] Don't honor user-supplied _failure_path on failure_forward
[CVE-2026-48489]
Checksums-Sha1:
f30a1f2090a15fcc1672754a9afaf6e816b0c803 19155 symfony_7.4.13+dfsg-1.dsc
fa33ef873f5b589c0fcd242cdbaf4dcca2179a3a 9390360 symfony_7.4.13+dfsg.orig.tar.xz
96ea1d4c0a5b47cbb0d1c0ace8086271002f69e4 81476 symfony_7.4.13+dfsg-1.debian.tar.xz
6e5617955c542a319f534097ce9bd853fd136964 74705 symfony_7.4.13+dfsg-1_amd64.buildinfo
Checksums-Sha256:
ac92e06605b20fe70cc97e23baf5573f7a231a5211d2bea3554080df1320de63 19155 symfony_7.4.13+dfsg-1.dsc
6b5e35da34fd7d59ba4db1d27299327f4a18315024109bef790efac1e02a1ea2 9390360 symfony_7.4.13+dfsg.orig.tar.xz
076269f69601d7646328d0d2952d87e18c30027415d247bd6ef4c86ecc4f7c74 81476 symfony_7.4.13+dfsg-1.debian.tar.xz
0d363d9f809733c7d480b37ff593a07bdd78e3dc2913f510875fa7d678d76f6f 74705 symfony_7.4.13+dfsg-1_amd64.buildinfo
Files:
66a742f055d9d087e9cbd237728a4513 19155 php optional symfony_7.4.13+dfsg-1.dsc
ff3c311eba0ca88b9fd2d3982d11774a 9390360 php optional symfony_7.4.13+dfsg.orig.tar.xz
f0f15f3f719b53da3336dabc3c674853 81476 php optional symfony_7.4.13+dfsg-1.debian.tar.xz
443ac9812ed16a7c1742aa55f011c1d7 74705 php optional symfony_7.4.13+dfsg-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQFGBAEBCgAwFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAmoXLQoSHHRhZmZpdEBk
ZWJpYW4ub3JnAAoJEAWMHPlE9r08Lp0H/jLFJ7S7TVX7wiIZKbCHKRH+ebUW8nNn
6dzjmLDM4sC+uozxxm7LUjLNrHH5TBQ4XMm6KUEzg1S7zB/B7UxTvQzH7W/3sOPQ
ckBF2o0hRADDKBWeP22APcWSFkPsgSTWQmc7oKiLLGrDQlasyQpY1yFKwthD+Kvx
VUol8Dp+4PUotF+5QqwxnyHJRIXCLbSnb0ayNjLpxu0GlKaTTG0FklNSZiEFO0/V
jDa9/KEgwfK6z2Xf3/sEEjgbmdWIWMIJPDaj+3Fu6C3DQ8NVaGua8/TjrcZ2X1bw
POImNm6F8S8m9gHTNRE8O4O3JPj2yG8brOfTo8vz28uYDvBRmarlK/o=
=ZCeO
-----END PGP SIGNATURE-----