@@ -7,6 +7,31 @@ in 6.4 minor versions.
77To get the diff for a specific change, go to https://github.com/symfony/symfony/commit/XXX where XXX is the change hash
88To get the diff between two versions, go to https://github.com/symfony/symfony/compare/v6.4.0...v6.4.1
99
10+ * 6.4.41 (2026-05-27)
11+
12+ * security #cve-2026 -48761 [ HtmlSanitizer] Sanitize URL attributes on <object >, <applet >, <iframe >, <img >, and the URL inside <meta http-equiv =" refresh " > content (nicolas-grekas)
13+ * security #cve-2026 -48760 [ HtmlSanitizer] Reject percent-encoded BiDi marks and Unicode whitespace in URLs (nicolas-grekas)
14+ * security #cve-2026 -48736 [ HttpFoundation] Block IPv6 transition forms in IpUtils::PRIVATE_SUBNETS (nicolas-grekas)
15+ * security #cve-2026 -48736 [ HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient (nicolas-grekas)
16+ * security #cve-2026 -48489 [ Security] Don't honor user-supplied _ failure_path on failure_forward (nicolas-grekas)
17+ * security #cve-2026 -48784 [ Routing] Fix dot-segment encoding for chained "../" and "./" in generated URLs (nicolas-grekas)
18+ * bug #64355 [ Console] Format message in ConsoleSectionOutput::overwrite() (nicolas-grekas)
19+ * bug #64349 [ HttpClient] ntlm regression on authPersistNonNTLM=false connections with reset() (Dooij)
20+ * bug #64348 [ FrameworkBundle] Allow to pass ` doctrine_open_transaction_logger ` ’s entity manager name positionally (MatTheCat)
21+ * bug #64335 [ Scheduler] Recover pending RecurringMessages after consumer stops midway (ousamabenyounes)
22+ * bug #64338 [ SecurityBundle] Fix Security::login() across firewalls (ousamabenyounes)
23+ * bug #64347 [ Process] Stop leaking CGI/FastCGI request-context vars to subprocesses (nicolas-grekas)
24+ * bug #64343 [ Mime] [ RateLimiter ] [ Routing] [ Security ] Harden __ unserialize against __ toString trampolines (nicolas-grekas)
25+ * bug #64342 [ HtmlSanitizer] Honor universal attribute sanitizers, apply maxInputLength to text contexts, document forceAttribute and allowAttribute caveats (nicolas-grekas)
26+ * bug #64341 [ FrameworkBundle] [ Mailer ] Harden default IP allowlist for Postmark and Brevo webhook parsers (nicolas-grekas)
27+ * bug #64337 [ Security] Initialize lazy users before serializing them (MatTheCat)
28+ * bug #64346 [ Runtime] Trust argv on CLI-like SAPIs to fix subprocess args (nicolas-grekas)
29+ * bug #64336 [ Cache] Accept '_ ' and ':' in prefix passed to AbstractAdapter::clear() (nicolas-grekas)
30+ * bug #64316 [ Yaml] Allow trailing newlines after the end-of-document marker (nicolas-grekas)
31+ * bug #64289 [ Translation] Don’t check the error message to know if Lokalise keys are missing (MatTheCat)
32+ * bug #64208 [ AssetMapper] Rewrite relative paths in ` export ... from ` statements (ousamabenyounes)
33+ * bug #64310 [ HttpKernel] [ WebProfilerBundle ] Check logs priority name for both ` WARNING ` and ` warning ` (MatTheCat)
34+
1035* 6.4.40 (2026-05-20)
1136
1237 * security #cve-2026 -46626 [ Runtime] Fix CVE-2024 -50340 patch bypass by gating argv on $_ SERVER[ 'QUERY_STRING'] (nicolas-grekas)
0 commit comments