Hi,
I have just submitted the PR symfony/symfony#60539 after a short discussion with the other Symfony Core Team members.
This is not a security vulnerability as already managed by modern web browsers (at lease starting from ~2018), but still considered a good practice by the OWASP.
I use the external redirects detection offered by this bundle and I am wondering if there is a way to ensure no opener is sent to the target and optout if needed.