GHSA-2xf4-cg6j-vhgq · 深刻度: low · エコシステム: composer — symfony/polyfill-intl-idn: xn-- labels with ASCII-only Punycode payloads are treated as equivalent to their decoded form
Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33 requirement that decoded ACE labels contain at least one non-ASCII code point. Originally unequal domain names can be regarded as equal, which can lead to blacklist bypassing, inconsistent URL parsing, and server-side request forgery in applications using the polyfill to canonicalise or compare hostnames. This issue is fixed in version 1.38.1.
総合評価: CVE-2026-46644 は低リスク(39/100)。CVSS 深刻度は中。悪用される可能性が高い(EPSS 0.39%、32 パーセンタイル) 推奨対応: 悪用情報と EPSS の推移を監視し、必要に応じて優先度を見直してください。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-07-15 | 0.14% | 0.39% | +0.26% |
| 2 | 2026-06-12 | — | 0.14% | — |
EPSS の全履歴 (全 2 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 6.9 | 4.0 | MEDIUM |
|
— | — | [email protected] |
GHSA-2xf4-cg6j-vhgq · 深刻度: low · エコシステム: composer — symfony/polyfill-intl-idn: xn-- labels with ASCII-only Punycode payloads are treated as equivalent to their decoded form
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-46644 not yet assigned priority: Debian including 1 source packages (php-symfony-polyfill), 4 status rows across 4 suites (bookworm, bullseye, forky, sid): open 2, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2026-46644 |
ubuntu
|
medium | CVE-2026-46644 medium priority: Ubuntu including 1 source packages (php-symfony-polyfill), 6 status rows across 6 suites (bionic, jammy, noble, questing, resolute, upstream): needs-triage 5, ignored 1. | https://ubuntu.com/security/CVE-2026-46644 |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| データセットに影響を受ける製品はありません。 | |||