PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution for an IN (...) list. This issue has been patched in version 1.33.0.
{ "binaries": [ { "binary_name": "php-pear", "binary_version": "1:1.10.5+submodules+notgz-1ubuntu1.18.04.4" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25236.json"
{ "binaries": [ { "binary_name": "php-pear", "binary_version": "1:1.10.9+submodules+notgz-1ubuntu0.20.04.3" } ] }
{ "binaries": [ { "binary_name": "php-pear", "binary_version": "1:1.10.12+submodules+notgz+20210212-1ubuntu3" } ] }
{ "binaries": [ { "binary_name": "php-pear", "binary_version": "1:1.10.13+submodules+notgz+2022032202-2build1" } ] }
{ "binaries": [ { "binary_name": "php-pear", "binary_version": "1:1.10.16+submodules+notgz-3" } ] }
{ "binaries": [ { "binary_name": "php-pear", "binary_version": "1:1.10.1+submodules+notgz-6ubuntu0.3+esm1" } ] }