Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
base-x homograph attack allows Unicode lookalike characters to bypass validation.
Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133