CVE-2026-71478: Php Unsafe Link Filter Bypasscve-2026-71478-php-unsafe-link-filter-bypass
Performing regex validation on a URL variable without prior stripping of control characters or whitespace allows attackers to bypass link filtering using obfuscated schemes (e.g., 'java\tscript:').