🔐 CVE-2026-46628: The `spaceless` filter implicitly marks its output as safe ➡️ https://symfony.com/blog/cve-2026-46628-the-spaceless-filter-implicitly-marks-its-output-as-safe
Post summary
Symfony’s blog post announces CVE-2026-46628, highlighting that the spaceless filter incorrectly treats its output as safe, thereby exposing a potential XSS vulnerability.
