News
Aggregated news about Symfony
Symfony on Medium
·
Symfony Blog
·
New in Symfony 8.1: Dependency Injection Improvements
The DependencyInjection component keeps evolving in Symfony 8.1 with several
quality-of-life improvements for autowiring, service decoration, tagged services,
and env vars.
Autowiring...
Symfony Blog
·
SymfonyOnline June 2026: Custom PHPStan Rules: Guardrails for AI-Assisted Symfony Code
SymfonyOnline June 2026 is officially scheduled for June 11 and 12, 2026! Join us online for two tracks of cutting-edge tech talks: one full day dedicated to AI and another full day...
Symfony Blog
·
New in Symfony 8.1: Improved JSON Streaming and Querying
Symfony includes two components dedicated to working with JSON:
JsonStreamer encodes PHP data into JSON and decodes JSON back into PHP
objects by streaming the contents, which...
Symfony Blog
·
CVE-2026-48805: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
Affected versions
Twig versions <=3.26.0 are affected by this security issue.
The issue has been fixed in Twig 3.27.0.
Description
The 3.26.0 source-policy hardening changed...
Symfony Blog
·
CVE-2026-46636: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders
Affected versions
Twig versions <=3.26.0 are affected by this security issue.
The issue has been fixed in Twig 3.27.0.
Description
The per-template filter, tag and function...
Symfony Blog
·
CVE-2026-48806: Sandbox `__toString()` policy bypass via dynamic mapping keys
Affected versions
Twig versions <=3.26.0 are affected by this security issue.
The issue has been fixed in Twig 3.27.0.
Description
This is a residual bypass of CVE-2026-47732...
Symfony Blog
·
CVE-2026-48807: Sandbox `__toString()` policy bypass via `Traversable` in `join`/`replace` and `in`/`not in` operators
Affected versions
Twig versions <=3.26.0 are affected by this security issue.
The issue has been fixed in Twig 3.27.0.
Description
This is a residual bypass of CVE-2026-47732...
Symfony Blog
·
CVE-2026-48808: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Affected versions
Twig versions <=3.26.0 are affected by this security issue.
The issue has been fixed in Twig 3.27.0.
Description
This is a residual bypass of CVE-2026-46635...
Symfony on Medium
·
The SOC 2 Blueprint: Beyond RBAC with AppLevel Encryption and Audit Isolation. Part #1
Symfony Blog
·
Symfony 8.1.0-RC1 released
Symfony 8.1.0-RC1 has just been released.
This is a pre-release version of Symfony 8.1. If you want to test it
in your own applications before its final release, run the following...
Symfony Blog
·
Symfony 8.0.13 released
Symfony 8.0.13 has just been released.
Read the Symfony upgrade guide to learn more about upgrading Symfony
and use the SymfonyInsight upgrade reports to detect the code you will
need...
Symfony Blog
·
CVE-2026-48747: Mailomat Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
Affected versions
Symfony versions >=7.2, <7.4.13, >=8.0, <8.0.13 of the Symfony Mailomat
Mailer component are affected by this security issue.
The issue has been...
Symfony Blog
·
CVE-2026-48761: HtmlSanitizer Misses URL Attributes on object, applet, iframe, img and meta refresh
Affected versions
Symfony versions >=6.1, <6.4.41, >=7, <7.4.13, >=8, <8.0.13 of the Symfony
HTML Sanitizer component are affected by this security issue....
Symfony Blog
·
CVE-2026-48736: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms: SSRF Bypass in NoPrivateNetworkHttpClient
Affected versions
Symfony versions >=6.4, <6.4.41, >=7.0, <7.4.13, >=8.0, <8.0.13 of the
Symfony HTTP Client and Symfony HTTP Foundation components are...
Symfony Blog
·
CVE-2026-48784: UrlGenerator Encoding Skips Every Other Chained ../ or ./: Generated URL Collapses Off-Route
Affected versions
Symfony versions <5.4.53, >=6, <6.4.41, >=7, <7.4.13, >=8, <8.0.13 of the
Symfony Routing component are affected by this security...
Symfony Blog
·
CVE-2026-48760: HtmlSanitizer URL Parser Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass
Affected versions
Symfony versions >=6.1, <6.4.41, >=7, <7.4.13, >=8, <8.0.13 of the Symfony
HTML Sanitizer component are affected by this security issue....
Symfony on Medium
·
Symfony UX Changed What Twig Can Do. Most Developers Missed It
Symfony Blog
·
SymfonyOnline June 2026: Symfony AI: Platform, Agent, and Store
Get ready for SymfonyOnline June 2026 This event will bring the international PHP community together online from June 11 to 12, 2026. This year, we are shaking things up with a brand-new...
Symfony on Medium
·
How to properly test PHP without database dependencies
Latest jobs
🛡Entreprendre l'Avenir - Marques Simplis et Stello🛡️
**Développeur Backend PHP / Symfony Senior**
- Full time
- Full Remote en France (1 journée par mois à Paris - déplacements, hôtel et transport pris en charge)
🚐 Camping-Car Park 🚐
Lead Développeur·euse PHP/Symfony
- Full time
- Paris 2/3 Jours de TT + quelques déplacements à Pornic au début de la mission.