{"id":"CVE-2026-46644","aliases":["GHSA-2xf4-cg6j-vhgq"],"url":"https://o3.security/vulnerability/CVE-2026-46644","summary":"symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence","details":"Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33 requirement that decoded ACE labels contain at least one non-ASCII code point. Originally unequal domain names can be regarded as equal, which can lead to blacklist bypassing, inconsistent URL parsing, and server-side request forgery in applications using the polyfill to canonicalise or compare hostnames. This issue is fixed in version 1.38.1.","published":"2026-07-14T20:48:31.771Z","modified":"2026-08-12T03:51:18.650967266Z","cvss":null,"epss":{"score":0.00394,"percentile":0.32694,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"symfony/polyfill","fixedVersion":"1.38.1"},{"ecosystem":"Packagist","name":"symfony/polyfill-intl-idn","fixedVersion":"1.38.1"}],"fix":{"url":"https://github.com/symfony/polyfill/commit/1be936e2491ccebe152bd736dfc91eb1422c8bec","label":"symfony/polyfill@1be936e"},"references":[{"type":"WEB","url":"https://github.com/symfony/polyfill/releases/tag/v1.38.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46644.json"},{"type":"ADVISORY","url":"https://github.com/symfony/polyfill/security/advisories/GHSA-2xf4-cg6j-vhgq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46644"},{"type":"FIX","url":"https://github.com/symfony/polyfill/commit/1be936e2491ccebe152bd736dfc91eb1422c8bec"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:18.650967266Z"}}