Skip to content

Releases: symfony/html-sanitizer

v8.1.0

29 May 08:53
v8.1.0

Choose a tag to compare

Changelog (v8.1.0-RC1...v8.1.0)

  • no significant changes

v8.1.0-RC1

27 May 11:34
v8.1.0-RC1

Choose a tag to compare

Changelog (v8.1.0-BETA3...v8.1.0-RC1)

  • security #cve-2026-48761 Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas)
  • security #cve-2026-48760 Reject percent-encoded BiDi marks and Unicode whitespace in URLs (@nicolas-grekas)
  • bug #64342 Honor universal attribute sanitizers, apply maxInputLength to text contexts, document forceAttribute and allowAttribute caveats (@nicolas-grekas)

v8.0.13

27 May 10:31
v8.0.13

Choose a tag to compare

Changelog (v8.0.12...v8.0.13)

  • security #cve-2026-48761 Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas)
  • security #cve-2026-48760 Reject percent-encoded BiDi marks and Unicode whitespace in URLs (@nicolas-grekas)
  • bug #64342 Honor universal attribute sanitizers, apply maxInputLength to text contexts, document forceAttribute and allowAttribute caveats (@nicolas-grekas)

v7.4.13

27 May 08:45
v7.4.13

Choose a tag to compare

Changelog (v7.4.12...v7.4.13)

  • security #cve-2026-48761 Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas)
  • security #cve-2026-48760 Reject percent-encoded BiDi marks and Unicode whitespace in URLs (@nicolas-grekas)
  • bug #64342 Honor universal attribute sanitizers, apply maxInputLength to text contexts, document forceAttribute and allowAttribute caveats (@nicolas-grekas)

v6.4.41

27 May 08:30
v6.4.41

Choose a tag to compare

Changelog (v6.4.40...v6.4.41)

  • security #cve-2026-48761 Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas)
  • security #cve-2026-48760 Reject percent-encoded BiDi marks and Unicode whitespace in URLs (@nicolas-grekas)
  • bug #64342 Honor universal attribute sanitizers, apply maxInputLength to text contexts, document forceAttribute and allowAttribute caveats (@nicolas-grekas)

v8.1.0-BETA3

20 May 12:11
v8.1.0-BETA3

Choose a tag to compare

Changelog (v8.1.0-BETA1...v8.1.0-BETA3)

v8.0.12

20 May 10:07
v8.0.12

Choose a tag to compare

Changelog (v8.0.7...v8.0.12)

v7.4.12

20 May 09:43
v7.4.12

Choose a tag to compare

Changelog (v7.4.7...v7.4.12)

v6.4.40

20 May 09:02
v6.4.40

Choose a tag to compare

Changelog (v6.4.35...v6.4.40)

v8.1.0-BETA1

06 May 14:28
v8.1.0-BETA1

Choose a tag to compare

Create tag v8.1.0-BETA1