{"id":"GHSA-2xf4-cg6j-vhgq","summary":"symfony/polyfill-intl-idn: xn-- labels with ASCII-only Punycode payloads are treated as equivalent to their decoded form","details":"### Description\n\n`symfony/polyfill-intl-idn` provides a userland implementation of `idn_to_utf8()` and `idn_to_ascii()` for runtimes that lack the `intl` extension. Its `Idn::process()` method decodes labels prefixed with `xn--` using Punycode but never enforces the validity criterion added in UTS #46 revision 33 Section 4 step 4.1.2: after a successful Punycode decode, the result must contain at least one non-ASCII code point.\n\nAs a consequence, `xn--` labels whose Punycode payload is empty (`xn--`) or decodes to a string made of only ASCII code points (e.g. `xn--kc1zs4-`) are accepted by the polyfill while PHP's native `ext-intl` rejects them with `IDNA_ERROR_INVALID_ACE_LABEL`. Originally unequal domain names are therefore regarded as equal, which can lead to blacklist bypassing, inconsistent URL parsing and server-side request forgery (similar to CVE-2024-12224).\n\nExample with `IDNA_USE_STD3_RULES | IDNA_CHECK_BIDI | IDNA_CHECK_CONTEXTJ | IDNA_NONTRANSITIONAL_TO_ASCII`:\n\n| Input | Polyfill output | Native `ext-intl` output |\n| --- | --- | --- |\n| `poc.xn--kc1zs4-.com` | `poc.kc1zs4.com` | `false` (`errors=1024`) |\n| `poc.kc1zs4.xn--` | `poc.kc1zs4.` | `false` (`errors=1024`) |\n\nApplications using the polyfill to canonicalise or compare hostnames inherit the inconsistency.\n\n### Resolution\n\n`Idn::process()` now records `IDNA_ERROR_INVALID_ACE_LABEL` when a Punycode payload decodes to an empty string or to a string containing only ASCII code points, matching the native `ext-intl` behaviour and UTS #46 revision 33.\n\nThe patch for this issue is available [here](https://github.com/symfony/polyfill/commit/1be936e2491ccebe152bd736dfc91eb1422c8bec) for branch 1.x.\n\n### Credits\n\nSymfony would like to thank Nazy Mad for reporting the issue and Nicolas Grekas for providing the fix.","aliases":["CVE-2026-46644"],"modified":"2026-09-10T03:51:04.192819875Z","published":"2026-05-28T19:52:36Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-1289"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-05-28T19:52:36Z"},"references":[{"type":"WEB","url":"https://github.com/symfony/polyfill/security/advisories/GHSA-2xf4-cg6j-vhgq"},{"type":"WEB","url":"https://github.com/symfony/polyfill/commit/1be936e2491ccebe152bd736dfc91eb1422c8bec"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/polyfill-intl-idn/CVE-2026-46644.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/polyfill/CVE-2026-46644.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/polyfill"},{"type":"WEB","url":"https://symfony.com/cve-2026-46644"}],"affected":[{"package":{"name":"symfony/polyfill","ecosystem":"Packagist","purl":"pkg:composer/symfony/polyfill"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.17.1"},{"fixed":"1.38.1"}]}],"versions":["v1.17.1","v1.18.0","v1.18.1","v1.19.0","v1.20.0","v1.22.0","v1.22.1","v1.23.0","v1.23.1","v1.24.0","v1.25.0","v1.26.0","v1.27.0","v1.28.0","v1.29.0","v1.30.0","v1.31.0","v1.32.0","v1.33.0","v1.34.0","v1.35.0","v1.36.0","v1.37.0","v1.38.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-2xf4-cg6j-vhgq/GHSA-2xf4-cg6j-vhgq.json"}},{"package":{"name":"symfony/polyfill-intl-idn","ecosystem":"Packagist","purl":"pkg:composer/symfony/polyfill-intl-idn"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.17.1"},{"fixed":"1.38.1"}]}],"versions":["v1.17.1","v1.18.0","v1.18.1","v1.19.0","v1.20.0","v1.22.0","v1.22.1","v1.23.0","v1.24.0","v1.25.0","v1.26.0","v1.27.0","v1.28.0","v1.29.0","v1.30.0","v1.31.0","v1.32.0","v1.33.0","v1.34.0","v1.35.0","v1.36.0","v1.37.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-2xf4-cg6j-vhgq/GHSA-2xf4-cg6j-vhgq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:U"}]}