News
Aggregated news about Symfony
Symfony Blog
·
Symfony 8.1.0 is about to be released. As for any other Symfony release, our
backward compatibility promise applies and this means that you should be able to
upgrade easily to 8.1...
Symfony Blog
·
Symfony 8.1.0 released
Symfony 8.1.0 has just been released.
Check the New in Symfony 8.1 posts on this blog to learn about
the main features of this new stable release; or check the first beta release announcement...
Symfony Blog
·
CVE-2026-49211: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Affected versions
Symfony versions >=2.2.0, <2.36.0, >=3.0.0, <3.1.0 of the Symfony UX
Autocomplete component are affected by this security issue.
The issue has...
Symfony Blog
·
CVE-2026-49208: Format-less date LiveProps parsed with the permissive DateTime constructor
Affected versions
Symfony versions >=2.8.0, <2.36.0, >=3.0.0, <3.1.0 of the Symfony UX Live
Component component are affected by this security issue.
The issue has...
Symfony Blog
·
CVE-2026-49209: Denial of service in symfony/ux-live-component via unbounded batch action requests
Affected versions
Symfony versions >=2.5.0, <2.36.0, >=3.0.0, <3.1.0 of the Symfony UX Live
Component component are affected by this security issue.
The issue has...
Symfony Blog
·
CVE-2026-49216: XSS in symfony/ux-autocomplete via unescaped AJAX response data
Affected versions
Symfony versions >=2.2.0, <2.36.0, >=3.0.0, <3.1.0 of the Symfony UX
Autocomplete component are affected by this security issue.
The issue has...
Symfony Blog
·
CVE-2026-49212: LiveComponentHydrator HMAC checksum lacks component and slot binding
Affected versions
Symfony versions >=2.8.0, <2.36.0, >=3.0.0, <3.1.0 of the Symfony UX Live
Component component are affected by this security issue.
The issue has...
Symfony Blog
·
CVE-2026-49215: CSRF Protection Bypass in symfony/ux-live-component: Accept Header is CORS-Safelisted
Affected versions
Symfony versions >=2.22.0, <2.36.0, >=3.0.0, <3.1.0 of the Symfony UX Live
Component component are affected by this security issue.
The issue...
Symfony Blog
·
CVE-2026-49210: XSS in symfony/ux-live-component via attacker-controlled child component tag
Affected versions
Symfony versions >=2.8.0, <2.36.0, >=3.0.0, <3.1.0 of the Symfony UX Live
Component component are affected by this security issue.
The issue has...
Symfony on Medium
·
An Open-Source Log, Metrics, and Performance Suite for OroCommerce
Symfony on Medium
·
Stop Answering the Same Support Tickets — Let Symfony AI Do It
Symfony Blog
·
SymfonyOnline June 2026: Giving voice to your agents, the Symfony AI way
Save the date! SymfonyOnline June 2026 will take place online on June 11-12, 2026, with 15 expert speakers streaming directly to you.
🎤 Speaker announcement!
Guillaume Loulier, Technical...
Symfony on Medium
·
The Laravel Lang Supply Chain Attack
Symfony on Medium
·
Getting Agent-Ready with Symfony
Symfony Blog
·
New in Symfony 8.1: Dependency Injection Improvements
The DependencyInjection component keeps evolving in Symfony 8.1 with several
quality-of-life improvements for autowiring, service decoration, tagged services,
and env vars.
Autowiring...
Symfony Blog
·
SymfonyOnline June 2026: Custom PHPStan Rules: Guardrails for AI-Assisted Symfony Code
SymfonyOnline June 2026 is officially scheduled for June 11 and 12, 2026! Join us online for two tracks of cutting-edge tech talks: one full day dedicated to AI and another full day...
Symfony Blog
·
New in Symfony 8.1: Improved JSON Streaming and Querying
Symfony includes two components dedicated to working with JSON:
JsonStreamer encodes PHP data into JSON and decodes JSON back into PHP
objects by streaming the contents, which...
Symfony Blog
·
CVE-2026-48808: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Affected versions
Twig versions <=3.26.0 are affected by this security issue.
The issue has been fixed in Twig 3.27.0.
Description
This is a residual bypass of CVE-2026-46635...
Symfony Blog
·
CVE-2026-46636: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders
Affected versions
Twig versions <=3.26.0 are affected by this security issue.
The issue has been fixed in Twig 3.27.0.
Description
The per-template filter, tag and function...
Symfony Blog
·
CVE-2026-48807: Sandbox `__toString()` policy bypass via `Traversable` in `join`/`replace` and `in`/`not in` operators
Affected versions
Twig versions <=3.26.0 are affected by this security issue.
The issue has been fixed in Twig 3.27.0.
Description
This is a residual bypass of CVE-2026-47732...
Latest jobs
🚐 Camping-Car Park 🚐
Lead Développeur·euse PHP/Symfony
- Full time
- Paris 2/3 Jours de TT + quelques déplacements à Pornic au début de la mission.