CVE-2026-46644Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33 requirement that decoded ACE labels contain at least one non-ASCII code point. Originally unequal domain names can be regarded as equal, which can lead to blacklist bypassing, inconsistent URL parsing, and server-side request forgery in applications using the polyfill to canonicalise or compare hostnames. This issue is fixed in version 1.38.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1289

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-26); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-26: 1Mentions · 2026-05-29: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-29: 105-2605-29
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Symfony@symfony
    Disclosure

    📢 CVE-2026-46644: insecure equivalence in symfony/polyfill-intl-idn for ASCII-only xn-- labels https://symfony.com/blog/cve-2026-46644-insecure-equivalence-in-symfony-polyfill-intl-idn-for-ascii-only-xn-labels

    Post summary

    The symfony blog post announces the disclosure of CVE-2026-46644, detailing an insecure equivalence flaw in the polyfill‐intl‐idn package for ASCII‑only xn‑ labels.

    0401201.7K
    45.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Symfony polyfill-intl-idn, IDN Punycode Validation Bypass, #CVE-2026-46644 (Medium) -DC-May2026-23 https://dailycve.com/symfony-polyfill-intl-idn-idn-punycode-validation-bypass-cve-2026-46644-medium-dc-may2026-23/

    Post summary

    A medium‑severity IDN Punycode validation bypass vulnerability (CVE‑2026‑46644) was disclosed for Symfony’s polyfill‑intl‑idn component, referenced via a DailyCVE link.

    00000327
    207 followersView on X

Explore more