CVE-2026-46644

Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33 requirement that decoded ACE labels contain at least one non-ASCII code point. Originally unequal domain names can be regarded as equal, which can lead to blacklist bypassing, inconsistent URL parsing, and server-side request forgery in applications using the polyfill to canonicalise or compare hostnames. This issue is fixed in version 1.38.1.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 21:16

Updated : 2026-07-15 18:16


NVD link : CVE-2026-46644

Mitre link : CVE-2026-46644

CVE.ORG link : CVE-2026-46644


JSON object : View

Products Affected

No product.

CWE
CWE-1289

Improper Validation of Unsafe Equivalence in Input