DEBIAN-CVE-2026-41570

Source
https://security-tracker.debian.org/tracker/CVE-2026-41570
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41570.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-41570
Upstream
Withdrawn
2026-06-01T14:01:36Z
Published
2026-05-08T15:16:40Z
Modified
2026-06-01T14:01:36Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=value command-line arguments without neutralizing INI metacharacters. Because PHP's INI parser interprets " as a string delimiter, ; as the start of a comment, and most importantly a newline as a directive separator, a value containing a newline is parsed by the child process as multiple INI directives. An attacker able to influence a single INI value can therefore inject arbitrary additional directives into the child's configuration, including auto_prepend_file, extension, disable_functions, open_basedir, and others. Setting auto_prepend_file to an attacker-controlled path yields remote code execution in the child process. This issue has been patched in versions 12.5.22 and 13.1.6.

References

Affected packages

Debian:11 / phpunit

Package

Name
phpunit
Purl
pkg:deb/debian/phpunit?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

9.*
9.5.2-1
9.5.2-1+deb11u1
9.5.3-1
9.5.4-1
9.5.5-1
9.5.6-1
9.5.7-1
9.5.10-1
9.5.11-1
9.5.12-1
9.5.13-1
9.5.14-1
9.5.16-1
9.5.20-1
9.5.20-2
9.5.20-3
9.5.21-1
9.5.23-1
9.5.24-1
9.5.24-2
9.5.24-3
9.5.25-1
9.5.26-1
9.5.27-1
9.5.28-1
9.6.0-1
9.6.1-1
9.6.3-1
9.6.4-1
9.6.5-1
9.6.6-1
9.6.7-1
9.6.9-1
9.6.10-1
9.6.11-1
9.6.12-1
9.6.13-1
9.6.15-1
9.6.16-1
9.6.17-1
9.6.18-1
9.6.19-1
9.6.20-1
9.6.21-1
9.6.22-1
10.*
10.0.7-1
10.0.9-1
10.0.11-1
10.0.12-1
10.0.13-1
10.0.14-1
10.0.15-1
10.0.16-1
10.0.18-1
10.0.19-1
10.1.2-1
10.1.3-1
10.2.0-1
10.2.1-1
10.2.2-1
10.2.3-1
10.2.4-1
10.2.5-1
10.2.6-1
10.3.1-1
10.3.2-1
10.3.3-1
10.3.4-1
10.3.5-1
10.4.0-1
10.4.1-1
10.4.2-1
10.5.1-1
10.5.2-1
10.5.3-1
10.5.5-1
10.5.6-1
10.5.7-1
10.5.8-1
10.5.9-1
11.*
11.0.1-1
11.0.2-1
11.0.3-1
11.0.4-1
11.0.5-1
11.0.6-1
11.0.8-1
11.0.9-1
11.1.1-1
11.1.2-1
11.1.3-1
11.2.2-1
11.2.5-1
11.2.6-1
11.2.7-1
11.2.8-1
11.3.0-1
11.3.1-1
11.3.3-1
11.3.4-1
11.3.5-1
11.3.6-1
11.4.1-1
11.4.2-1
11.4.3-1
11.4.4-1
11.5.2-1
11.5.2-2
11.5.2-3
11.5.2-4
11.5.3-1
11.5.5-1
11.5.6-1
11.5.7-1
11.5.8-1
11.5.9-1
11.5.10-1
11.5.12-1
11.5.12-2
11.5.13-1
11.5.14-1
11.5.15-1
11.5.17-1
11.5.18-1
11.5.19-1
12.*
12.0.2-1
12.0.3-1
12.0.4-1
12.0.5-1
12.0.7-1
12.0.7-2
12.0.8-1
12.0.9-1
12.0.10-1
12.1.0-1
12.1.2-1
12.1.3-1
12.1.4-1
12.1.5-1
12.1.6-1
12.2.1-1
12.2.2-1
12.2.3-1
12.2.5-1
12.2.6-1
12.2.7-1
12.3.0-1
12.3.3-1
12.3.4-1
12.3.5-1
12.3.6-1
12.3.7-1
12.3.8-1
12.3.11-1
12.3.12-1
12.3.14-1
12.3.15-1
12.3.15-2
12.4.0-1
12.4.1-1
12.4.2-1
12.4.3-1
12.4.4-1
12.4.5-1
12.5.1-1
12.5.2-1
12.5.3-1
12.5.4-1
12.5.5-1
12.5.6-1
12.5.7-1
12.5.8-1
12.5.9-1
13.*
13.0.0-1
13.0.0-2
13.0.1-1
13.0.2-1
13.0.3-1
13.0.5-1
13.0.6-1
13.0.6-2
13.0.6-3
13.1.0-1
13.1.1-1
13.1.3-1
13.1.5-1
13.1.6-1
13.1.7-1
13.1.8+ds-1
13.1.9+ds-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41570.json"

Debian:12 / phpunit

Package

Name
phpunit
Purl
pkg:deb/debian/phpunit?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

9.*
9.6.7-1
9.6.7-1+deb12u1
9.6.9-1
9.6.10-1
9.6.11-1
9.6.12-1
9.6.13-1
9.6.15-1
9.6.16-1
9.6.17-1
9.6.18-1
9.6.19-1
9.6.20-1
9.6.21-1
9.6.22-1
10.*
10.0.7-1
10.0.9-1
10.0.11-1
10.0.12-1
10.0.13-1
10.0.14-1
10.0.15-1
10.0.16-1
10.0.18-1
10.0.19-1
10.1.2-1
10.1.3-1
10.2.0-1
10.2.1-1
10.2.2-1
10.2.3-1
10.2.4-1
10.2.5-1
10.2.6-1
10.3.1-1
10.3.2-1
10.3.3-1
10.3.4-1
10.3.5-1
10.4.0-1
10.4.1-1
10.4.2-1
10.5.1-1
10.5.2-1
10.5.3-1
10.5.5-1
10.5.6-1
10.5.7-1
10.5.8-1
10.5.9-1
11.*
11.0.1-1
11.0.2-1
11.0.3-1
11.0.4-1
11.0.5-1
11.0.6-1
11.0.8-1
11.0.9-1
11.1.1-1
11.1.2-1
11.1.3-1
11.2.2-1
11.2.5-1
11.2.6-1
11.2.7-1
11.2.8-1
11.3.0-1
11.3.1-1
11.3.3-1
11.3.4-1
11.3.5-1
11.3.6-1
11.4.1-1
11.4.2-1
11.4.3-1
11.4.4-1
11.5.2-1
11.5.2-2
11.5.2-3
11.5.2-4
11.5.3-1
11.5.5-1
11.5.6-1
11.5.7-1
11.5.8-1
11.5.9-1
11.5.10-1
11.5.12-1
11.5.12-2
11.5.13-1
11.5.14-1
11.5.15-1
11.5.17-1
11.5.18-1
11.5.19-1
12.*
12.0.2-1
12.0.3-1
12.0.4-1
12.0.5-1
12.0.7-1
12.0.7-2
12.0.8-1
12.0.9-1
12.0.10-1
12.1.0-1
12.1.2-1
12.1.3-1
12.1.4-1
12.1.5-1
12.1.6-1
12.2.1-1
12.2.2-1
12.2.3-1
12.2.5-1
12.2.6-1
12.2.7-1
12.3.0-1
12.3.3-1
12.3.4-1
12.3.5-1
12.3.6-1
12.3.7-1
12.3.8-1
12.3.11-1
12.3.12-1
12.3.14-1
12.3.15-1
12.3.15-2
12.4.0-1
12.4.1-1
12.4.2-1
12.4.3-1
12.4.4-1
12.4.5-1
12.5.1-1
12.5.2-1
12.5.3-1
12.5.4-1
12.5.5-1
12.5.6-1
12.5.7-1
12.5.8-1
12.5.9-1
13.*
13.0.0-1
13.0.0-2
13.0.1-1
13.0.2-1
13.0.3-1
13.0.5-1
13.0.6-1
13.0.6-2
13.0.6-3
13.1.0-1
13.1.1-1
13.1.3-1
13.1.5-1
13.1.6-1
13.1.7-1
13.1.8+ds-1
13.1.9+ds-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41570.json"

Debian:13 / phpunit

Package

Name
phpunit
Purl
pkg:deb/debian/phpunit?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

11.*
11.5.19-1
11.5.19-1+deb13u1
12.*
12.0.2-1
12.0.3-1
12.0.4-1
12.0.5-1
12.0.7-1
12.0.7-2
12.0.8-1
12.0.9-1
12.0.10-1
12.1.0-1
12.1.2-1
12.1.3-1
12.1.4-1
12.1.5-1
12.1.6-1
12.2.1-1
12.2.2-1
12.2.3-1
12.2.5-1
12.2.6-1
12.2.7-1
12.3.0-1
12.3.3-1
12.3.4-1
12.3.5-1
12.3.6-1
12.3.7-1
12.3.8-1
12.3.11-1
12.3.12-1
12.3.14-1
12.3.15-1
12.3.15-2
12.4.0-1
12.4.1-1
12.4.2-1
12.4.3-1
12.4.4-1
12.4.5-1
12.5.1-1
12.5.2-1
12.5.3-1
12.5.4-1
12.5.5-1
12.5.6-1
12.5.7-1
12.5.8-1
12.5.9-1
13.*
13.0.0-1
13.0.0-2
13.0.1-1
13.0.2-1
13.0.3-1
13.0.5-1
13.0.6-1
13.0.6-2
13.0.6-3
13.1.0-1
13.1.1-1
13.1.3-1
13.1.5-1
13.1.6-1
13.1.7-1
13.1.8+ds-1
13.1.9+ds-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41570.json"

Debian:14 / phpunit

Package

Name
phpunit
Purl
pkg:deb/debian/phpunit?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

11.*
11.5.19-1
12.*
12.0.2-1
12.0.3-1
12.0.4-1
12.0.5-1
12.0.7-1
12.0.7-2
12.0.8-1
12.0.9-1
12.0.10-1
12.1.0-1
12.1.2-1
12.1.3-1
12.1.4-1
12.1.5-1
12.1.6-1
12.2.1-1
12.2.2-1
12.2.3-1
12.2.5-1
12.2.6-1
12.2.7-1
12.3.0-1
12.3.3-1
12.3.4-1
12.3.5-1
12.3.6-1
12.3.7-1
12.3.8-1
12.3.11-1
12.3.12-1
12.3.14-1
12.3.15-1
12.3.15-2
12.4.0-1
12.4.1-1
12.4.2-1
12.4.3-1
12.4.4-1
12.4.5-1
12.5.1-1
12.5.2-1
12.5.3-1
12.5.4-1
12.5.5-1
12.5.6-1
12.5.7-1
12.5.8-1
12.5.9-1
13.*
13.0.0-1
13.0.0-2
13.0.1-1
13.0.2-1
13.0.3-1
13.0.5-1
13.0.6-1
13.0.6-2
13.0.6-3
13.1.0-1
13.1.1-1
13.1.3-1
13.1.5-1
13.1.6-1
13.1.7-1
13.1.8+ds-1
13.1.9+ds-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41570.json"