Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass ...
Continue reading
A security flaw has been identified in specific versions of PHP, the open-source software that powers most dynamic websites. The issue impacts PHP 8.4.* releases older than 8.4.21 and PHP 8.5.* releases older than 8.5.6.The vulnerability is triggered when a specially crafted input containing a hidden null byte is sent to common PHP tools used for ...
Continue reading
A security flaw has been identified in specific versions of PHP, the software that powers most dynamic, interactive websites. The issue affects PHP 8.2 versions older than 8.2.31, 8.3 versions older than 8.3.31, 8.4 versions older than 8.4.21, and 8.5 versions older than 8.5.6.
This flaw only impacts websites that use PHP's SOAP server feature ...
Continue reading
A security flaw has been identified in specific versions of PHP, the software that powers most dynamic websites and web applications. The affected versions are all 8.2 releases older than 8.2.31, all 8.3 releases older than 8.3.31, all 8.4 releases older than 8.4.21, and all 8.5 releases older than 8.5.6.
The issue is a flaw in PHP's SOAP ...
Continue reading