Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-x7rj-f32v-7jjg
  • Packagist/phalcon/cphalcon
Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS 28 Aug
  • Fix available
  • Severity - 8.7 (High)
GHSA-8jqh-95g6-7jpj
  • Packagist/phalcon/cphalcon
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel) 28 Aug
  • Fix available
  • Severity - 8.2 (High)
GHSA-hrwp-4hh9-c8r8
  • Packagist/phalcon/cphalcon
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE) 21 Aug
  • Fix available
  • Severity - 9.2 (Critical)
CVE-2026-59989
  • github.com/phalcon/cphalcon
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE) 21 Aug
  • Fix available
  • Severity - 9.2 (Critical)
CVE-2026-57584
  • github.com/phalcon/cphalcon
Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS 10 Jul
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-54736
  • github.com/phalcon/cphalcon
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel) 10 Jul
  • Fix available
  • Severity - 8.2 (High)