PKSA-y6py-qpv1-h52p Security Advisory
-
CVE-2026-48736: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
PKSA-y6py-qpv1-h52p CVE-2026-48736
Affected package: symfony/http-foundation
Affected version: >=6.4.0,<6.4.41|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.13|>=8.0.0,<8.0.13
Reported by:
FriendsOfPHP/security-advisories