|
32668
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
GitHub, Inc.
Base Score:
7.8 HIGH
7.8 HIGH
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32668
|
|
32669
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
Summarize page
Summarize page...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32669
|
|
32670
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New chat
Gemini
PRO
PRO
Conversation with Gemini
Conversation with Gemini
Hi Lukas
Where should we start?
Where should we start?
🖼️ Create image, button, tap to use tool
🖼️ Create image
🎸 Create music, button, tap to use tool
🎸 Create music
Boost my day, button, tap to use tool
Boost my day
Help me learn, button, tap to use tool
Help me learn
Write anything, button, tap to use tool
Write anything
Ask Gemini
encrypted
Ask Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Microphone
Send message
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
GitHub, Inc.
Base Score:
7.8 HIGH
7.8 HIGH
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
URL
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
Source(s)
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
CVE
Tag(s)
Patch
Release Notes
Release Notes
Release Notes
Release Notes
Release Notes
Mitigation
Vendor Advisory
Mailing List
Third Party Advisory
Weakness Enumeration
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
CWE-ID
CWE-502
CWE-502
CWE Name
Deserialization of Untrusted Data
Source
GitHub, Inc.
Known Affected Software Configurations Switch to CPE 2.2
Known Affected Software Configurations
Switch to CPE 2.2
Switch to CPE 2.2
Configuration 1
(
hide
hide
)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
Up to (excluding)
8.5.52
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
9.0.0
Up to (excluding)
9.6.33
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
10.0.0
Up to (excluding)
10.5.62
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
11.0.0
Up to (excluding)
11.5.50
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
12.0.0
Up to (excluding)
12.5.8
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32670
|
|
32671
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New chat
Gemini
PRO
PRO
Conversation with Gemini
Conversation with Gemini
Hi Lukas
Where should we start?
Where should we start?
🖼️ Create image, button, tap to use tool
🖼️ Create image
🎸 Create music, button, tap to use tool
🎸 Create music
Boost my day, button, tap to use tool
Boost my day
Help me learn, button, tap to use tool
Help me learn
Write anything, button, tap to use tool
Write anything
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Microphone
Send message
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
GitHub, Inc.
Base Score:
7.8 HIGH
7.8 HIGH
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
URL
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
Source(s)
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
CVE
Tag(s)
Patch
Release Notes
Release Notes
Release Notes
Release Notes
Release Notes
Mitigation
Vendor Advisory
Mailing List
Third Party Advisory
Weakness Enumeration
Weakness Enumeration
CWE-ID...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32671
|
|
32672
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New chat
Gemini
PRO
PRO
Conversation with Gemini
Conversation with Gemini
Copy prompt
Edit
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Gemini is typing
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
GitHub, Inc.
Base Score:
7.8 HIGH
7.8 HIGH
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
URL
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
Source(s)
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
CVE
Tag(s)
Patch
Release Notes
Release Notes
Release Notes
Release Notes
Release Notes
Mitigation
Vendor Advisory
Mailing List
Third Party Advisory
Weakness Enumeration
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
CWE-ID
CWE-502
CWE-502
CWE Name
Deserialization of Untrusted Data
Source
GitHub, Inc.
Known Affected Software Configurations Switch to CPE 2.2
Known Affected Software Configurations
Switch to CPE 2.2
Switch to CPE 2.2
Configuration 1
(
hide
hide
)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
Up to (excluding)
8.5.52
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
9.0.0
Up to (excluding)
9.6.33
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
10.0.0
Up to (excluding)
10.5.62
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
11.0.0
Up to (excluding)
11.5.50
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
12.0.0
Up to (excluding)
12.5.8
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
Up to (excluding)
8.5.52
From (including)
9.0.0
From (including)
10.0.0
From (including)
11.0.0
From (including)
12.0.0
Up to (excluding)
9.6.33
Up to (excluding)
10.5.62
Up to (excluding)
11.5.50
Up to (excluding)
12.5.8
Configuration 2
(
hide
hide
)
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Show Matching CPE(s)
Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know
Are we missing a CPE here? Please let us know
.
Change History
Change History
3 change records found
show changes
show changes
QUICK INFO
QUICK INFO
CVE Dictionary Entry:
CVE-2026-24765
CVE-2026-24765
NVD Published Date:
01/27/2026
NVD Last Modified:
03/03/2026
Source:
GitHub, Inc.
X (link is external)
X
(link is external)
facebook (link is external)
facebook
(link is external)
linkedin (link is external)
linkedin
(link is external)...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32672
|
|
32673
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
Edit
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Gemini replied
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
GitHub, Inc.
Base Score:
7.8 HIGH
7.8 HIGH
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
URL
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
Source(s)
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
CVE
Tag(s)
Patch
Release Notes
Release Notes
Release Notes
Release Notes
Release Notes
Mitigation
Vendor Advisory
Mailing List
Third Party Advisory
Weakness Enumeration
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
CWE-ID
CWE-502
CWE-502
CWE Name
Deserialization of Untrusted Data
Source
GitHub, Inc.
Known Affected Software Configurations Switch to CPE 2.2
Known Affected Software Configurations
Switch to CPE 2.2
Switch to CPE 2.2
Configuration 1
(
hide
hide
)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
Up to (excluding)
8.5.52
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
9.0.0
Up to (excluding)
9.6.33
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
10.0.0
Up to (excluding)
10.5.62
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
11.0.0
Up to (excluding)
11.5.50
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
12.0.0
Up to (excluding)
12.5.8
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
Up to (excluding)
8.5.52
From (including)
9.0.0
From (including)
10.0.0
From (including)
11.0.0
From (including)
12.0.0
Up to (excluding)
9.6.33
Up to (excluding)
10.5.62
Up to (excluding)
11.5.50...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32673
|
|
32674
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
Edit
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
,
a popular testing framework for PHP.
The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Gemini replied
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
GitHub, Inc.
Base Score:
7.8 HIGH
7.8 HIGH
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
URL
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
Source(s)
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
CVE
Tag(s)
Patch
Release Notes
Release Notes
Release Notes
Release Notes
Release Notes
Mitigation
Vendor Advisory
Mailing List
Third Party Advisory
Weakness Enumeration
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
CWE-ID
CWE-502
CWE-502
CWE Name
Deserialization of Untrusted Data
Source
GitHub, Inc.
Known Affected Software Configurations Switch to CPE 2.2
Known Affected Software Configurations
Switch to CPE 2.2
Switch to CPE 2.2
Configuration 1
(
hide
hide
)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
Up to (excluding)
8.5.52
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
9.0.0
Up to (excluding)
9.6.33
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
10.0.0
Up to (excluding)
10.5.62
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
11.0.0
Up to (excluding)
11.5.50
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:*
Show Matching CPE(s)
Show Matching CPE(s)
From (including)
12.0.0
Up to (excluding)
12.5.8
...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32674
|
|
32675
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
Edit
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
,
a popular testing framework for PHP.
The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled,
it deserializes the malicious file.
If the object contains a
__wakeup()
magic method,
it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.
5.
8
11.x:
Before 11.
5.
50
10.x:
Before 10.
5.
62
9.x:
Before 9.
6.
33
8.x:
Before 8.
5.
52
Risk Assessment
Risk Assessment
CVSS Score:
7.
8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files.
Common threat environments include compromised CI/CD pipelines,
local development machines,
or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD,
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
GitHub, Inc.
Base Score:
7.8 HIGH
7.8 HIGH
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc....
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32675
|
|
32676
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
Edit
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
,
a popular testing framework for PHP.
The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled,
it deserializes the malicious file.
If the object contains a
__wakeup()
magic method,
it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.
5.
8
11.x:
Before 11.
5.
50
10.x:
Before 10.
5.
62
9.x:
Before 9.
6.
33
8.x:
Before 8.
5.
52
Risk Assessment
Risk Assessment
CVSS Score:
7.
8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files.
Common threat environments include compromised CI/CD pipelines,
local development machines,
or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD,
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32676
|
|
32677
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled, it deserializes the malicious file. If the object contains a
__wakeup()
magic method, it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.5.8
11.x:
Before 11.5.50
10.x:
Before 10.5.62
9.x:
Before 9.6.33
8.x:
Before 8.5.52
Risk Assessment
Risk Assessment
CVSS Score:
7.8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files. Common threat environments include compromised CI/CD pipelines, local development machines, or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD, such as using ephemeral runners and strict access controls.
Enforce code reviews and branch protection to prevent malicious file injection.
Good response
Bad response
Share & export
Copy
Show more options
Copy prompt
Edit
You said how can I fix these vulnareabilities in laravel project
You said
how can I fix these vulnareabilities in laravel project
Refining the Response
Gemini said
Gemini said
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
GitHub, Inc.
Base Score:
7.8 HIGH
7.8 HIGH
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
URL
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32677
|
|
32678
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled, it deserializes the malicious file. If the object contains a
__wakeup()
magic method, it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.5.8
11.x:
Before 11.5.50
10.x:
Before 10.5.62
9.x:
Before 9.6.33
8.x:
Before 8.5.52
Risk Assessment
Risk Assessment
CVSS Score:
7.8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files. Common threat environments include compromised CI/CD pipelines, local development machines, or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD, such as using ephemeral runners and strict access controls.
Enforce code reviews and branch protection to prevent malicious file injection.
Good response
Bad response
Share & export
Copy
Show more options
Copy prompt
Edit
You said how can I fix these vulnareabilities in laravel project
You said
how can I fix these vulnareabilities in laravel project
Refining the Response
Gemini said
Gemini said
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32678
|
|
32679
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled, it deserializes the malicious file. If the object contains a
__wakeup()
magic method, it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.5.8
11.x:
Before 11.5.50
10.x:
Before 10.5.62
9.x:
Before 9.6.33
8.x:
Before 8.5.52
Risk Assessment
Risk Assessment
CVSS Score:
7.8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files. Common threat environments include compromised CI/CD pipelines, local development machines, or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD, such as using ephemeral runners and strict access controls.
Enforce code reviews and branch protection to prevent malicious file injection.
Good response
Bad response
Share & export
Copy
Show more options
Copy prompt
Edit
You said how can I fix these vulnareabilities in laravel project
You said
how can I fix these vulnareabilities in laravel project
Listen
Show thinking
Gemini said
Gemini said
Fixing this vulnerability in a Laravel project is a very straightforward process. In Laravel, PHPUnit is managed as a development dependency via Composer, so resolving the issue simply requires updating that package to a patched version.
Here is exactly how to secure your project:
1. Check Your Current Version
1. Check Your Current Version
First, verify which version of PHPUnit your Laravel application is currently using. Run this command in your terminal at the root of your project:
Bash
Download code
Copy code
composer show phpunit/phpunit
Look at the
versions
line in the output to see if you are running a vulnerable version (anything lower than 12.5.8, 11.5.50, 10.5.62, 9.6.33, or 8.5.52).
2. Update PHPUnit
2. Update PHPUnit
Tell Composer to update PHPUnit and its associated dependencies to the latest secure versions allowed by your
composer.json
constraints:
Bash
Download code
Copy code
composer update phpunit/phpunit --with-dependencies
Note: If your
composer.json
restricts PHPUnit to an older major version (like
^9.0
), Composer will automatically grab the secure patch for that specific major version (e.g., 9.6.33).
3. Verify the Fix
3. Verify the Fix
Run the
composer show
command from step one again to confirm the version has been bumped. As long as your version is at or above one of the secure releases listed above, you are protected against CVE-2026-24765.
4. Secure Your Environments
4. Secure Your Environments
Because PHPUnit lives in the
require-dev
block of your
composer.json
, this vulnerability does not impact your production environment—
provided you are deploying correctly
.
Always build your production environment using
composer install --no-dev --optimize-autoloader
. This ensures testing frameworks are completely excluded from your live servers.
For your CI/CD pipelines, ensure you are using ephemeral runners (runners that spin up fresh for every job and are destroyed afterward) so that an attacker cannot leave a malicious
.coverage
file behind for a subsequent test run to execute.
Would you like me to walk you through how to verify that your production server is completely free of development dependencies?
Good response
Bad response
Redo
Share & export
Copy
Show more options
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Microphone
Send message
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
GitHub, Inc.
Base Score:
7.8 HIGH
7.8 HIGH
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32679
|
|
32680
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled, it deserializes the malicious file. If the object contains a
__wakeup()
magic method, it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.5.8
11.x:
Before 11.5.50
10.x:
Before 10.5.62
9.x:
Before 9.6.33
8.x:
Before 8.5.52
Risk Assessment
Risk Assessment
CVSS Score:
7.8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files. Common threat environments include compromised CI/CD pipelines, local development machines, or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD, such as using ephemeral runners and strict access controls.
Enforce code reviews and branch protection to prevent malicious file injection.
Good response
Bad response
Share & export
Copy
Show more options
Copy prompt
Edit
You said how can I fix these vulnareabilities in laravel project
You said
how can I fix these vulnareabilities in laravel project
Listen
Show thinking
Gemini said
Gemini said
Fixing this vulnerability in a Laravel project is a very straightforward process. In Laravel, PHPUnit is managed as a development dependency via Composer, so resolving the issue simply requires updating that package to a patched version.
Here is exactly how to secure your project:
1. Check Your Current Version
1. Check Your Current Version
First, verify which version of PHPUnit your Laravel application is currently using. Run this command in your terminal at the root of your project:
Bash
Download code
Copy code...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32680
|
|
32681
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled, it deserializes the malicious file. If the object contains a
__wakeup()
magic method, it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.5.8
11.x:
Before 11.5.50
10.x:
Before 10.5.62
9.x:
Before 9.6.33
8.x:
Before 8.5.52
Risk Assessment
Risk Assessment
CVSS Score:
7.8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files. Common threat environments include compromised CI/CD pipelines, local development machines, or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD, such as using ephemeral runners and strict access controls.
Enforce code reviews and branch protection to prevent malicious file injection.
Good response
Bad response
Share & export
Copy
Show more options
Copy prompt
Edit
You said how can I fix these vulnareabilities in laravel project
You said
how can I fix these vulnareabilities in laravel project
Listen
Show thinking
Gemini said
Gemini said
Fixing this vulnerability in a Laravel project is a very straightforward process. In Laravel, PHPUnit is managed as a development dependency via Composer, so resolving the issue simply requires updating that package to a patched version.
Here is exactly how to secure your project:
1. Check Your Current Version
1. Check Your Current Version
First, verify which version of PHPUnit your Laravel application is currently using. Run this command in your terminal at the root of your project:
Bash
Download code
Copy code
composer show phpunit/phpunit
Look at the
versions
line in the output to see if you are running a vulnerable version (anything lower than 12.5.8, 11.5.50, 10.5.62, 9.6.33, or 8.5.52).
2. Update PHPUnit
2. Update PHPUnit
Tell Composer to update PHPUnit and its associated dependencies to the latest secure versions allowed by your
composer.json
constraints:
Bash
Download code
Copy code
composer update phpunit/phpunit --with-dependencies
Note: If your
composer.json
restricts PHPUnit to an older major version (like
^9.0
), Composer will automatically grab the secure patch for that specific major version (e.g., 9.6.33).
3. Verify the Fix
3. Verify the Fix
Run the
composer show
command from step one again to confirm the version has been bumped. As long as your version is at or above one of the secure releases listed above, you are protected against CVE-2026-24765.
4. Secure Your Environments
4. Secure Your Environments
Because PHPUnit lives in the
require-dev
block of your
composer.json
, this vulnerability does not impact your production environment—
provided you are deploying correctly
.
Always build your production environment using
composer install --no-dev --optimize-autoloader
. This ensures testing frameworks are completely excluded from your live servers.
For your CI/CD pipelines, ensure you are using ephemeral runners (runners that spin up fresh for every job and are destroyed afterward) so that an attacker cannot leave a malicious
.coverage
file behind for a subsequent test run to execute.
Would you like me to walk you through how to verify that your production server is completely free of development dependencies?
Good response
Bad response
Redo
Share & export
Copy
Show more options
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Microphone
Send message
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32681
|
|
32703
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32703
|
|
32704
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled, it deserializes the malicious file. If the object contains a
__wakeup()
magic method, it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.5.8
11.x:
Before 11.5.50
10.x:
Before 10.5.62
9.x:
Before 9.6.33
8.x:
Before 8.5.52
Risk Assessment
Risk Assessment
CVSS Score:
7.8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files. Common threat environments include compromised CI/CD pipelines, local development machines, or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD, such as using ephemeral runners and strict access controls.
Enforce code reviews and branch protection to prevent malicious file injection.
Good response
Bad response
Share & export
Copy
Show more options
Copy prompt
Edit
You said how can I fix these vulnareabilities in laravel project
You said
how can I fix these vulnareabilities in laravel project
Listen
Show thinking
Gemini said
Gemini said
Fixing this vulnerability in a Laravel project is a very straightforward process. In Laravel, PHPUnit is managed as a development dependency via Composer, so resolving the issue simply requires updating that package to a patched version.
Here is exactly how to secure your project:
1. Check Your Current Version
1. Check Your Current Version
First, verify which version of PHPUnit your Laravel application is currently using. Run this command in your terminal at the root of your project:
Bash
Download code
Copy code
composer show phpunit/phpunit
Look at the
versions
line in the output to see if you are running a vulnerable version (anything lower than 12.5.8, 11.5.50, 10.5.62, 9.6.33, or 8.5.52).
2. Update PHPUnit...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32704
|
|
32714
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32714
|
|
32715
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32715
|
|
32716
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled, it deserializes the malicious file. If the object contains a
__wakeup()
magic method, it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.5.8
11.x:
Before 11.5.50
10.x:
Before 10.5.62
9.x:
Before 9.6.33
8.x:
Before 8.5.52
Risk Assessment
Risk Assessment
CVSS Score:
7.8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files. Common threat environments include compromised CI/CD pipelines, local development machines, or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD, such as using ephemeral runners and strict access controls.
Enforce code reviews and branch protection to prevent malicious file injection.
Good response
Bad response
Share & export
Copy
Show more options
Copy prompt
Edit
You said how can I fix these vulnareabilities in laravel project
You said
how can I fix these vulnareabilities in laravel project
Listen
Show thinking
Gemini said
Gemini said
Fixing this vulnerability in a Laravel project is a very straightforward process. In Laravel, PHPUnit is managed as a development dependency via Composer, so resolving the issue simply requires updating that package to a patched version.
Here is exactly how to secure your project:
1. Check Your Current Version
1. Check Your Current Version
First, verify which version of PHPUnit your Laravel application is currently using. Run this command in your terminal at the root of your project:
Bash
Download code
Copy code
composer show phpunit/phpunit
Look at the
versions
line in the output to see if you are running a vulnerable version (anything lower than 12.5.8, 11.5.50, 10.5.62, 9.6.33, or 8.5.52).
2. Update PHPUnit
2. Update PHPUnit
Tell Composer to update PHPUnit and its associated dependencies to the latest secure versions allowed by your
composer.json
constraints:
Bash
Download code
Copy code
composer update phpunit/phpunit --with-dependencies
Note: If your
composer.json
restricts PHPUnit to an older major version (like
^9.0
), Composer will automatically grab the secure patch for that specific major version (e.g., 9.6.33).
3. Verify the Fix
3. Verify the Fix
Run the
composer show
command from step one again to confirm the version has been bumped. As long as your version is at or above one of the secure releases listed above, you are protected against CVE-2026-24765.
4. Secure Your Environments
4. Secure Your Environments
Because PHPUnit lives in the
require-dev
block of your
composer.json
, this vulnerability does not impact your production environment—
provided you are deploying correctly
.
Always build your production environment using
composer install --no-dev --optimize-autoloader
. This ensures testing frameworks are completely excluded from your live servers.
For your CI/CD pipelines, ensure you are using ephemeral runners (runners that spin up fresh for every job and are destroyed afterward) so that an attacker cannot leave a malicious
.coverage
file behind for a subsequent test run to execute.
Would you like me to walk you through how to verify that your production server is completely free of development dependencies?
Good response
Bad response
Redo
Share & export
Copy
Show more options
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Microphone
Send message
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
GitHub, Inc.
Base Score:
7.8 HIGH
7.8 HIGH
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32716
|
|
32717
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled, it deserializes the malicious file. If the object contains a
__wakeup()
magic method, it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.5.8
11.x:
Before 11.5.50
10.x:
Before 10.5.62
9.x:
Before 9.6.33
8.x:
Before 8.5.52
Risk Assessment
Risk Assessment
CVSS Score:
7.8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files. Common threat environments include compromised CI/CD pipelines, local development machines, or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD, such as using ephemeral runners and strict access controls.
Enforce code reviews and branch protection to prevent malicious file injection.
Good response
Bad response
Share & export
Copy
Show more options
Copy prompt
Edit
You said how can I fix these vulnareabilities in laravel project
You said
how can I fix these vulnareabilities in laravel project
Listen
Show thinking
Gemini said
Gemini said
Fixing this vulnerability in a Laravel project is a very straightforward process. In Laravel, PHPUnit is managed as a development dependency via Composer, so resolving the issue simply requires updating that package to a patched version.
Here is exactly how to secure your project:
1. Check Your Current Version
1. Check Your Current Version
First, verify which version of PHPUnit your Laravel application is currently using. Run this command in your terminal at the root of your project:
Bash
Download code
Copy code
composer show phpunit/phpunit
Look at the
versions
line in the output to see if you are running a vulnerable version (anything lower than 12.5.8, 11.5.50, 10.5.62, 9.6.33, or 8.5.52).
2. Update PHPUnit
2. Update PHPUnit
Tell Composer to update PHPUnit and its associated dependencies to the latest secure versions allowed by your
composer.json
constraints:
Bash
Download code
Copy code
composer update phpunit/phpunit --with-dependencies
Note: If your
composer.json
restricts PHPUnit to an older major version (like
^9.0
), Composer will automatically grab the secure patch for that specific major version (e.g., 9.6.33).
3. Verify the Fix
3. Verify the Fix
Run the
composer show
command from step one again to confirm the version has been bumped. As long as your version is at or above one of the secure releases listed above, you are protected against CVE-2026-24765.
4. Secure Your Environments
4. Secure Your Environments
Because PHPUnit lives in the
require-dev
block of your
composer.json
, this vulnerability does not impact your production environment—
provided you are deploying correctly
.
Always build your production environment using
composer install --no-dev --optimize-autoloader
. This ensures testing frameworks are completely excluded from your live servers.
For your CI/CD pipelines, ensure you are using ephemeral runners (runners that spin up fresh for every job and are destroyed afterward) so that an attacker cannot leave a malicious
.coverage
file behind for a subsequent test run to execute.
Would you like me to walk you through how to verify that your production server is completely free of development dependencies?
Good response
Bad response
Redo
Share & export
Copy
Show more options
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Microphone
Send message
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control....
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32717
|
|
32718
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) [URL_WITH_CREDENTIALS] composer show phpunit/phpunit name : phpunit/phpunit descrip. : The PHP Unit Testing framework. keywords : phpunit, testing, xunit versions : * 11.5.55 type : library license : BSD 3-Clause "New" or "Revised" License (BSD-3-Clause) (OSI approved) [URL_WITH_CREDENTIALS] composer show phpunit/phpunit
name : phpunit/phpunit
descrip. : The PHP Unit Testing framework.
keywords : phpunit, testing, xunit
versions : * 11.5.55
type : library
license : BSD 3-Clause "New" or "Revised" License (BSD-3-Clause) (OSI approved) https://spdx.org/licenses/BSD-3-Clause.html#licenseText
homepage : https://phpunit.de/
source : [git] https://github.com/sebastianbergmann/phpunit.git adc7262fccc12de2b30f12a8aa0b33775d814f00
dist : [zip] https://api.github.com/repos/sebastianbergmann/phpunit/zipball/adc7262fccc12de2b30f12a8aa0b33775d814f00 adc7262fccc12de2b30f12a8aa0b33775d814f00
path : /home/jiminny/vendor/phpunit/phpunit
names : phpunit/phpunit
support
issues : https://github.com/sebastianbergmann/phpunit/issues
security : https://github.com/sebastianbergmann/phpunit/security/policy
source : https://github.com/sebastianbergmann/phpunit/tree/11.5.55
autoload
files
classmap
src/
requires
ext-dom *
ext-json *
ext-libxml *
ext-mbstring *
ext-xml *
ext-xmlwriter *
myclabs/deep-copy ^1.13.4
phar-io/manifest ^2.0.4
phar-io/version ^3.2.1
php >=8.2
phpunit/php-code-coverage ^11.0.12
phpunit/php-file-iterator ^5.1.1
phpunit/php-invoker ^5.0.1
phpunit/php-text-template ^4.0.1
phpunit/php-timer ^7.0.1
sebastian/cli-parser ^3.0.2
sebastian/code-unit ^3.0.3
sebastian/comparator ^6.3.3
sebastian/diff ^6.0.2
sebastian/environment ^7.2.1
sebastian/exporter ^6.3.2
sebastian/global-state ^7.0.2
sebastian/object-enumerator ^6.0.1
sebastian/recursion-context ^6.0.3
sebastian/type ^5.1.3
sebastian/version ^5.0.2
staabm/side-effects-detector ^1.0.5
suggests
ext-soap To be able to generate mocks based on WSDL files
Expand
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Gemini is typing
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-24765 Detail
CVE-2026-24765
Detail
Description
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
GitHub, Inc.
Base Score:
7.8 HIGH
7.8 HIGH
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
URL
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
Source(s)
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
GitHub, Inc.
CVE
Tag(s)
Patch
Release Notes
Release Notes
Release Notes
Release Notes
Release Notes
Mitigation
Vendor Advisory
Mailing List
Third Party Advisory
Weakness Enumeration
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
CWE-ID
CWE-502
CWE-502
CWE Name
Deserialization of Untrusted Data...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32718
|
|
32721
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32721
|
|
32722
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32722
|
|
32723
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32723
|
|
32724
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled, it deserializes the malicious file. If the object contains a
__wakeup()
magic method, it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.5.8
11.x:
Before 11.5.50
10.x:
Before 10.5.62
9.x:
Before 9.6.33
8.x:
Before 8.5.52
Risk Assessment
Risk Assessment
CVSS Score:
7.8 (High)...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32724
|
|
32725
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) [URL_WITH_CREDENTIALS] composer show phpunit/phpunit name : phpunit/phpunit descrip. : The PHP Unit Testing framework. keywords : phpunit, testing, xunit versions : * 11.5.55 type : library license : BSD 3-Clause "New" or "Revised" License (BSD-3-Clause) (OSI approved) [URL_WITH_CREDENTIALS] composer show phpunit/phpunit
name : phpunit/phpunit
descrip. : The PHP Unit Testing framework.
keywords : phpunit, testing, xunit
versions : * 11.5.55
type : library
license : BSD 3-Clause "New" or "Revised" License (BSD-3-Clause) (OSI approved) https://spdx.org/licenses/BSD-3-Clause.html#licenseText
homepage : https://phpunit.de/
source : [git] https://github.com/sebastianbergmann/phpunit.git adc7262fccc12de2b30f12a8aa0b33775d814f00
dist : [zip] https://api.github.com/repos/sebastianbergmann/phpunit/zipball/adc7262fccc12de2b30f12a8aa0b33775d814f00 adc7262fccc12de2b30f12a8aa0b33775d814f00
path : /home/jiminny/vendor/phpunit/phpunit
names : phpunit/phpunit
support
issues : https://github.com/sebastianbergmann/phpunit/issues
security : https://github.com/sebastianbergmann/phpunit/security/policy
source : https://github.com/sebastianbergmann/phpunit/tree/11.5.55
autoload
files
classmap
src/
requires
ext-dom *
ext-json *
ext-libxml *
ext-mbstring *
ext-xml *
ext-xmlwriter *
myclabs/deep-copy ^1.13.4
phar-io/manifest ^2.0.4
phar-io/version ^3.2.1
php >=8.2
phpunit/php-code-coverage ^11.0.12
phpunit/php-file-iterator ^5.1.1
phpunit/php-invoker ^5.0.1
phpunit/php-text-template ^4.0.1
phpunit/php-timer ^7.0.1
sebastian/cli-parser ^3.0.2
sebastian/code-unit ^3.0.3
sebastian/comparator ^6.3.3
sebastian/diff ^6.0.2
sebastian/environment ^7.2.1
sebastian/exporter ^6.3.2
sebastian/global-state ^7.0.2
sebastian/object-enumerator ^6.0.1
sebastian/recursion-context ^6.0.3
sebastian/type ^5.1.3
sebastian/version ^5.0.2
staabm/side-effects-detector ^1.0.5
suggests
ext-soap To be able to generate mocks based on WSDL files
Expand
Show thinking
Gemini said
Gemini said
Assessment: Safe
Assessment: Safe
Based on the terminal output you provided,
your Laravel project is
not vulnerable
to CVE-2026-24765.
Your Installed Version:
11.5.55
Secure Patched Version:
11.5.50
(for the 11.
x release branch)
Because you are running
11.5.55
,
which is newer than the required security patch,
the unsafe deserialization flaw in the
cleanupForCoverage()
method has already been resolved in your environment.
You don't need to take any further action to upgrade PHPUnit for this specific CVE.
A quick reminder on best practices:
Since you are running this inside a Docker container (
docker_lamp_1
),
just ensure that when you build your production container images,
you continue to use the
--no-dev
flag with Composer.
This guarantees that PHPUnit is entirely excluded from your live production environments.
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Pro
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Summarize page...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32725
|
|
32726
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32726
|
|
32727
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc....
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32727
|
|
32728
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) [URL_WITH_CREDENTIALS] composer show phpunit/phpunit name : phpunit/phpunit descrip. : The PHP Unit Testing framework. keywords : phpunit, testing, xunit versions : * 11.5.55 type : library license : BSD 3-Clause "New" or "Revised" License (BSD-3-Clause) (OSI approved) [URL_WITH_CREDENTIALS] composer show phpunit/phpunit
name : phpunit/phpunit
descrip. : The PHP Unit Testing framework.
keywords : phpunit, testing, xunit
versions : * 11.5.55
type : library
license : BSD 3-Clause "New" or "Revised" License (BSD-3-Clause) (OSI approved) https://spdx.org/licenses/BSD-3-Clause.html#licenseText
homepage : https://phpunit.de/
source : [git] https://github.com/sebastianbergmann/phpunit.git adc7262fccc12de2b30f12a8aa0b33775d814f00
dist : [zip] https://api.github.com/repos/sebastianbergmann/phpunit/zipball/adc7262fccc12de2b30f12a8aa0b33775d814f00 adc7262fccc12de2b30f12a8aa0b33775d814f00
path : /home/jiminny/vendor/phpunit/phpunit
names : phpunit/phpunit
support
issues : https://github.com/sebastianbergmann/phpunit/issues
security : https://github.com/sebastianbergmann/phpunit/security/policy
source : https://github.com/sebastianbergmann/phpunit/tree/11.5.55
autoload
files...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32728
|
|
32729
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) [URL_WITH_CREDENTIALS] composer show phpunit/phpunit name : phpunit/phpunit descrip. : The PHP Unit Testing framework. keywords : phpunit, testing, xunit versions : * 11.5.55 type : library license : BSD 3-Clause "New" or "Revised" License (BSD-3-Clause) (OSI approved) [URL_WITH_CREDENTIALS] composer show phpunit/phpunit
name : phpunit/phpunit
descrip. : The PHP Unit Testing framework.
keywords : phpunit, testing, xunit
versions : * 11.5.55
type : library
license : BSD 3-Clause "New" or "Revised" License (BSD-3-Clause) (OSI approved) https://spdx.org/licenses/BSD-3-Clause.html#licenseText
homepage : https://phpunit.de/
source : [git] https://github.com/sebastianbergmann/phpunit.git adc7262fccc12de2b30f12a8aa0b33775d814f00
dist : [zip] https://api.github.com/repos/sebastianbergmann/phpunit/zipball/adc7262fccc12de2b30f12a8aa0b33775d814f00 adc7262fccc12de2b30f12a8aa0b33775d814f00
path : /home/jiminny/vendor/phpunit/phpunit...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32729
|
|
32730
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled, it deserializes the malicious file. If the object contains a
__wakeup()
magic method, it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.5.8
11.x:
Before 11.5.50
10.x:
Before 10.5.62
9.x:
Before 9.6.33
8.x:
Before 8.5.52
Risk Assessment
Risk Assessment
CVSS Score:
7.8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files. Common threat environments include compromised CI/CD pipelines, local development machines, or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD, such as using ephemeral runners and strict access controls.
Enforce code reviews and branch protection to prevent malicious file injection.
Good response
Bad response
Share & export
Copy
Show more options
Copy prompt
You said how can I fix these vulnareabilities in laravel project
You said
how can I fix these vulnareabilities in laravel project
Listen
Show thinking
Gemini said
Gemini said
Fixing this vulnerability in a Laravel project is a very straightforward process. In Laravel, PHPUnit is managed as a development dependency via Composer, so resolving the issue simply requires updating that package to a patched version.
Here is exactly how to secure your project:
1. Check Your Current Version
1. Check Your Current Version
First, verify which version of PHPUnit your Laravel application is currently using. Run this command in your terminal at the root of your project:
Bash
Download code
Copy code
composer show phpunit/phpunit...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32730
|
|
32731
|
[JY-19967] Upgrade Python and libraries - Apr - Ji [JY-19967] Upgrade Python and libraries - Apr - Jira
[JY-19967] Upgrade Python and libraries - Apr - Jira
Dependabot alerts · jiminny/prophet
Dependabot alerts · jiminny/prophet
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-24765
NVD - cve-2026-24765
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-6722
NVD - cve-2026-6722
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
[JY-19957] Upgrade BE libraries - Apr - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
You said I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765 Detail Description PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. CNA: GitHub, Inc. Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda GitHub, Inc. Patch https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33 GitHub, Inc. Release Notes https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p GitHub, Inc. Mitigation Vendor Advisory https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html CVE Mailing List Third Party Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-502 Deserialization of Untrusted Data GitHub, Inc. Known Affected Software Configurations Switch to CPE 2.2 Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s) From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s) Denotes Vulnerable Software Are we missing a CPE here? Please let us know. Change History 3 change records found show changes Quick Info CVE Dictionary Entry: CVE-2026-24765 NVD Published Date: 01/27/2026 NVD Last Modified: 03/03/2026 Source: GitHub, Inc.</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-24765</tabTitle>” with “<selection>CVE-2026-24765
Detail
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base
Score: N/A
NVD assessment
not yet provided.
CNA: GitHub, Inc.
Base
Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda
GitHub, Inc.
Patch
https://github.com/sebastianbergmann/phpunit/releases/tag/10.5.63
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/11.5.50
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/12.5.8
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/8.5.52
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/releases/tag/9.6.33
GitHub, Inc.
Release Notes
https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
GitHub, Inc.
Mitigation
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/02/msg00009.html
CVE
Mailing List
Third Party Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-502
Deserialization of Untrusted Data
GitHub, Inc.
Known Affected Software Configurations Switch
to CPE 2.2
Configuration 1 ( hide ) cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
Up to (excluding)8.5.52 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)9.0.0Up to (excluding)9.6.33 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)10.0.0Up to (excluding)10.5.62 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)11.0.0Up to (excluding)11.5.50 cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* Show Matching CPE(s)
From (including)12.0.0Up to (excluding)12.5.8 Configuration 2 ( hide ) cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Show Matching CPE(s)
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
3 change records found show changes
Quick Info
CVE Dictionary Entry: CVE-2026-24765 NVD
Published Date: 01/27/2026 NVD
Last Modified: 03/03/2026
Source: GitHub, Inc.</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Listen
Gemini said
Gemini said
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
Summary of CVE-2026-24765: PHPUnit Insecure Deserialization
CVE-2026-24765 describes a high-severity security vulnerability in
PHPUnit
, a popular testing framework for PHP. The flaw allows for potential
Remote Code Execution (RCE)
through the unsafe handling of code coverage data.
Vulnerability Mechanism
Vulnerability Mechanism
Root Cause:
The
cleanupForCoverage()
method in PHPUnit performs deserialization on
.coverage
files during PHPT test execution without restricting the classes that can be instantiated (lacking the
allowed_classes
parameter).
Attack Vector:
An attacker with local file write access can place a malicious serialized PHP object into a
.coverage
file.
Impact:
When PHPUnit runs tests with code coverage instrumentation enabled, it deserializes the malicious file. If the object contains a
__wakeup()
magic method, it can trigger arbitrary code execution in the context of the user running the tests.
Affected Versions
Affected Versions
The vulnerability impacts versions prior to:
12.x:
Before 12.5.8
11.x:
Before 11.5.50
10.x:
Before 10.5.62
9.x:
Before 9.6.33
8.x:
Before 8.5.52
Risk Assessment
Risk Assessment
CVSS Score:
7.8 (High)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Requirement:
Requires local file write access to the directory where PHPUnit expects coverage files. Common threat environments include compromised CI/CD pipelines, local development machines, or malicious dependencies.
Resolution and Mitigation
Resolution and Mitigation
Official Patch:
The maintainer updated PHPUnit to treat pre-existing
.coverage
files as an error condition rather than attempting to sanitize and process them.
Recommended Actions:
* Update PHPUnit to the latest patched version in your respective release branch.
Implement security best practices in CI/CD, such as using ephemeral runners and strict access controls.
Enforce code reviews and branch protection to prevent malicious file injection.
Good response
Bad response
Share & export
Copy
Show more options
Copy prompt
You said how can I fix these vulnareabilities in laravel project
You said
how can I fix these vulnareabilities in laravel project
Listen
Show thinking
Gemini said
Gemini said
Fixing this vulnerability in a Laravel project is a very straightforward process. In Laravel, PHPUnit is managed as a development dependency via Composer, so resolving the issue simply requires updating that package to a patched version.
Here is exactly how to secure your project:
1. Check Your Current Version
1. Check Your Current Version
First, verify which version of PHPUnit your Laravel application is currently using. Run this command in your terminal at the root of your project:
Bash
Download code
Copy code
composer show phpunit/phpunit
Look at the
versions
line in the output to see if you are running a vulnerable version (anything lower than 12.5.8, 11.5.50, 10.5.62, 9.6.33, or 8.5.52).
2. Update PHPUnit
2. Update PHPUnit
Tell Composer to update PHPUnit and its associated dependencies to the latest secure versions allowed by your
composer.json
constraints:
Bash
Download code
Copy code
composer update phpunit/phpunit --with-dependencies
Note: If your
composer.json
restricts PHPUnit to an older major version (like
^9.0
), Composer will automatically grab the secure patch for that specific major version (e.g., 9.6.33).
3. Verify the Fix
3. Verify the Fix
Run the
composer show
command from step one again to confirm the version has been bumped. As long as your version is at or above one of the secure releases listed above, you are protected against CVE-2026-24765.
4. Secure Your Environments
4. Secure Your Environments
Because PHPUnit lives in the
require-dev
block of your
composer.json
, this vulnerability does not impact your production environment—
provided you are deploying correctly
.
Always build your production environment using
composer install --no-dev --optimize-autoloader
. This ensures testing frameworks are completely excluded from your live servers.
For your CI/CD pipelines, ensure you are using ephemeral runners (runners that spin up fresh for every job and are destroyed afterward) so that an attacker cannot leave a malicious
.coverage
file behind for a subsequent test run to execute.
Would you like me to walk you through how to verify that your production server is completely free of development dependencies?
Good response
Bad response
Share & export
Copy...
|
Firefox
|
NVD - cve-2026-24765 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-24765
|
32731
|
|
31627
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Open Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
Transferring data from nvd.nist.gov…...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31627
|
|
31628
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Open Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-23450 Detail
CVE-2026-23450
Detail
AWAITING ENRICHMENT
This CVE record has been marked for NVD enrichment efforts.
Description
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops->syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock pointer. However, when the SMC listen socket is being closed concurrently, smc_close_active() sets clcsock->sk_user_data to NULL under sk_callback_lock, and then the smc_sock itself can be freed via sock_put() in smc_release(). This leads to two issues: 1) NULL pointer dereference: sk_user_data is NULL when accessed. 2) Use-after-free: sk_user_data is read as non-NULL, but the smc_sock is freed before its fields (e.g., queued_smc_hs, ori_af_ops) are accessed. The race window looks like this (the syzkaller crash [1] triggers via the SYN cookie path: tcp_get_cookie_sock() -> smc_tcp_syn_recv_sock(), but the normal tcp_check_req() path has the same race): CPU A (softirq) CPU B (process ctx) tcp_v4_rcv() TCP_NEW_SYN_RECV: sk = req->rsk_listener sock_hold(sk) /* No lock on listener */ smc_close_active(): write_lock_bh(cb_lock) sk_user_data = NULL write_unlock_bh(cb_lock) ... smc_clcsock_release() sock_put(smc->sk) x2 -> smc_sock freed! tcp_check_req() smc_tcp_syn_recv_sock(): smc = user_data(sk) -> NULL or dangling smc->queued_smc_hs -> crash! Note that the clcsock and smc_sock are two independent objects with separate refcounts. TCP stack holds a reference on the clcsock, which keeps it alive, but this does NOT prevent the smc_sock from being freed. Fix this by using RCU and refcount_inc_not_zero() to safely access smc_sock. Since smc_tcp_syn_recv_sock() is called in the TCP three-way handshake path, taking read_lock_bh on sk_callback_lock is too heavy and would not survive a SYN flood attack. Using rcu_read_lock() is much more lightweight. - Set SOCK_RCU_FREE on the SMC listen socket so that smc_sock freeing is deferred until after the RCU grace period. This guarantees the memory is still valid when accessed inside rcu_read_lock(). - Use rcu_read_lock() to protect reading sk_user_data. - Use refcount_inc_not_zero(&smc->sk.sk_refcnt) to pin the smc_sock. If the refcount has already reached zero (close path completed), it returns false and we bail out safely. Note: smc_hs_congested() has a similar lockless read of sk_user_data without rcu_read_lock(), but it only checks for NULL and accesses the global smc_hs_wq, never dereferencing any smc_sock field, so it is not affected. Reproducer was verified with mdelay injection and smc_run, the issue no longer occurs with this patch applied. [1] https://syzkaller.appspot.com/bug?extid=827ae2bfb3a3529333e9
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
kernel.org
Base Score:
9.8 CRITICAL
9.8 CRITICAL
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
kernel.org
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
kernel.org
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
kernel.org
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
kernel.org
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
kernel.org
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
kernel.org
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
kernel.org
URL
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
Source(s)
kernel.org
kernel.org
kernel.org
kernel.org
kernel.org
kernel.org
kernel.org
Tag(s)
Weakness Enumeration
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-ID
CWE Name
Source
Change History
Change History
3 change records found
show changes
show changes
QUICK INFO
QUICK INFO
CVE Dictionary Entry:
CVE-2026-23450
CVE-2026-23450
NVD Published Date:
04/03/2026
NVD Last Modified:
04/27/2026
Source:
kernel.org
X (link is external)
X
(link is external)
facebook (link is external)
facebook
(link is external)
linkedin (link is external)
linkedin
(link is external)
youtube (link is external)
youtube
(link is external)
rss
rss
govdelivery (link is external)
govdelivery
(link is external)
HEADQUARTERS
100 Bureau Drive...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31628
|
|
31629
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Open Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-23450 Detail
CVE-2026-23450
Detail
AWAITING ENRICHMENT
This CVE record has been marked for NVD enrichment efforts.
Description
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops->syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock pointer. However, when the SMC listen socket is being closed concurrently, smc_close_active() sets clcsock->sk_user_data to NULL under sk_callback_lock, and then the smc_sock itself can be freed via sock_put() in smc_release(). This leads to two issues: 1) NULL pointer dereference: sk_user_data is NULL when accessed. 2) Use-after-free: sk_user_data is read as non-NULL, but the smc_sock is freed before its fields (e.g., queued_smc_hs, ori_af_ops) are accessed. The race window looks like this (the syzkaller crash [1] triggers via the SYN cookie path: tcp_get_cookie_sock() -> smc_tcp_syn_recv_sock(), but the normal tcp_check_req() path has the same race): CPU A (softirq) CPU B (process ctx) tcp_v4_rcv() TCP_NEW_SYN_RECV: sk = req->rsk_listener sock_hold(sk) /* No lock on listener */ smc_close_active(): write_lock_bh(cb_lock) sk_user_data = NULL write_unlock_bh(cb_lock) ... smc_clcsock_release() sock_put(smc->sk) x2 -> smc_sock freed! tcp_check_req() smc_tcp_syn_recv_sock(): smc = user_data(sk) -> NULL or dangling smc->queued_smc_hs -> crash! Note that the clcsock and smc_sock are two independent objects with separate refcounts. TCP stack holds a reference on the clcsock, which keeps it alive, but this does NOT prevent the smc_sock from being freed. Fix this by using RCU and refcount_inc_not_zero() to safely access smc_sock. Since smc_tcp_syn_recv_sock() is called in the TCP three-way handshake path, taking read_lock_bh on sk_callback_lock is too heavy and would not survive a SYN flood attack. Using rcu_read_lock() is much more lightweight. - Set SOCK_RCU_FREE on the SMC listen socket so that smc_sock freeing is deferred until after the RCU grace period. This guarantees the memory is still valid when accessed inside rcu_read_lock(). - Use rcu_read_lock() to protect reading sk_user_data. - Use refcount_inc_not_zero(&smc->sk.sk_refcnt) to pin the smc_sock. If the refcount has already reached zero (close path completed), it returns false and we bail out safely. Note: smc_hs_congested() has a similar lockless read of sk_user_data without rcu_read_lock(), but it only checks for NULL and accesses the global smc_hs_wq, never dereferencing any smc_sock field, so it is not affected. Reproducer was verified with mdelay injection and smc_run, the issue no longer occurs with this patch applied. [1] https://syzkaller.appspot.com/bug?extid=827ae2bfb3a3529333e9
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
kernel.org
Base Score:
9.8 CRITICAL
9.8 CRITICAL
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
kernel.org
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
kernel.org
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
kernel.org
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
kernel.org
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
kernel.org
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
kernel.org
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
kernel.org
URL
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
Source(s)
kernel.org
kernel.org
kernel.org
kernel.org
kernel.org
kernel.org
kernel.org
Tag(s)
Weakness Enumeration
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-ID
CWE Name
Source
Change History
Change History
3 change records found
show changes
show changes
QUICK INFO
QUICK INFO
CVE Dictionary Entry:
CVE-2026-23450
CVE-2026-23450
NVD Published Date:
04/03/2026
NVD Last Modified:
04/27/2026...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31629
|
|
31630
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Open Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-23450 Detail
CVE-2026-23450
Detail
AWAITING ENRICHMENT
This CVE record has been marked for NVD enrichment efforts.
Description
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops->syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock pointer. However, when the SMC listen socket is being closed concurrently, smc_close_active() sets clcsock->sk_user_data to NULL under sk_callback_lock, and then the smc_sock itself can be freed via sock_put() in smc_release(). This leads to two issues: 1) NULL pointer dereference: sk_user_data is NULL when accessed. 2) Use-after-free: sk_user_data is read as non-NULL, but the smc_sock is freed before its fields (e.g., queued_smc_hs, ori_af_ops) are accessed. The race window looks like this (the syzkaller crash [1] triggers via the SYN cookie path: tcp_get_cookie_sock() -> smc_tcp_syn_recv_sock(), but the normal tcp_check_req() path has the same race): CPU A (softirq) CPU B (process ctx) tcp_v4_rcv() TCP_NEW_SYN_RECV: sk = req->rsk_listener sock_hold(sk) /* No lock on listener */ smc_close_active(): write_lock_bh(cb_lock) sk_user_data = NULL write_unlock_bh(cb_lock) ... smc_clcsock_release() sock_put(smc->sk) x2 -> smc_sock freed! tcp_check_req() smc_tcp_syn_recv_sock(): smc = user_data(sk) -> NULL or dangling smc->queued_smc_hs -> crash! Note that the clcsock and smc_sock are two independent objects with separate refcounts. TCP stack holds a reference on the clcsock, which keeps it alive, but this does NOT prevent the smc_sock from being freed. Fix this by using RCU and refcount_inc_not_zero() to safely access smc_sock. Since smc_tcp_syn_recv_sock() is called in the TCP three-way handshake path, taking read_lock_bh on sk_callback_lock is too heavy and would not survive a SYN flood attack. Using rcu_read_lock() is much more lightweight. - Set SOCK_RCU_FREE on the SMC listen socket so that smc_sock freeing is deferred until after the RCU grace period. This guarantees the memory is still valid when accessed inside rcu_read_lock(). - Use rcu_read_lock() to protect reading sk_user_data. - Use refcount_inc_not_zero(&smc->sk.sk_refcnt) to pin the smc_sock. If the refcount has already reached zero (close path completed), it returns false and we bail out safely. Note: smc_hs_congested() has a similar lockless read of sk_user_data without rcu_read_lock(), but it only checks for NULL and accesses the global smc_hs_wq, never dereferencing any smc_sock field, so it is not affected. Reproducer was verified with mdelay injection and smc_run, the issue no longer occurs with this patch applied. [1] https://syzkaller.appspot.com/bug?extid=827ae2bfb3a3529333e9
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
kernel.org
Base Score:
9.8 CRITICAL
9.8 CRITICAL
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
kernel.org
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
kernel.org
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
kernel.org
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
kernel.org
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
kernel.org
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
kernel.org
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
kernel.org
URL
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
Source(s)
kernel.org
kernel.org
kernel.org
kernel.org
kernel.org
kernel.org
kernel.org
Tag(s)
Weakness Enumeration
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-ID
CWE Name
Source
Change History
Change History
3 change records found
show changes
show changes
QUICK INFO
QUICK INFO
CVE Dictionary Entry:
CVE-2026-23450...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31630
|
|
31631
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Open Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-23450 Detail
CVE-2026-23450
Detail
AWAITING ENRICHMENT
This CVE record has been marked for NVD enrichment efforts.
Description
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops->syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock pointer. However, when the SMC listen socket is being closed concurrently, smc_close_active() sets clcsock->sk_user_data to NULL under sk_callback_lock, and then the smc_sock itself can be freed via sock_put() in smc_release(). This leads to two issues: 1) NULL pointer dereference: sk_user_data is NULL when accessed. 2) Use-after-free: sk_user_data is read as non-NULL, but the smc_sock is freed before its fields (e.g., queued_smc_hs, ori_af_ops) are accessed. The race window looks like this (the syzkaller crash [1] triggers via the SYN cookie path: tcp_get_cookie_sock() -> smc_tcp_syn_recv_sock(), but the normal tcp_check_req() path has the same race): CPU A (softirq) CPU B (process ctx) tcp_v4_rcv() TCP_NEW_SYN_RECV: sk = req->rsk_listener sock_hold(sk) /* No lock on listener */ smc_close_active(): write_lock_bh(cb_lock) sk_user_data = NULL write_unlock_bh(cb_lock) ... smc_clcsock_release() sock_put(smc->sk) x2 -> smc_sock freed! tcp_check_req() smc_tcp_syn_recv_sock(): smc = user_data(sk) -> NULL or dangling smc->queued_smc_hs -> crash! Note that the clcsock and smc_sock are two independent objects with separate refcounts. TCP stack holds a reference on the clcsock, which keeps it alive, but this does NOT prevent the smc_sock from being freed. Fix this by using RCU and refcount_inc_not_zero() to safely access smc_sock. Since smc_tcp_syn_recv_sock() is called in the TCP three-way handshake path, taking read_lock_bh on sk_callback_lock is too heavy and would not survive a SYN flood attack. Using rcu_read_lock() is much more lightweight. - Set SOCK_RCU_FREE on the SMC listen socket so that smc_sock freeing is deferred until after the RCU grace period. This guarantees the memory is still valid when accessed inside rcu_read_lock(). - Use rcu_read_lock() to protect reading sk_user_data. - Use refcount_inc_not_zero(&smc->sk.sk_refcnt) to pin the smc_sock. If the refcount has already reached zero (close path completed), it returns false and we bail out safely. Note: smc_hs_congested() has a similar lockless read of sk_user_data without rcu_read_lock(), but it only checks for NULL and accesses the global smc_hs_wq, never dereferencing any smc_sock field, so it is not affected. Reproducer was verified with mdelay injection and smc_run, the issue no longer occurs with this patch applied. [1] https://syzkaller.appspot.com/bug?extid=827ae2bfb3a3529333e9
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31631
|
|
31632
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Open Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-23450 Detail
CVE-2026-23450
Detail
AWAITING ENRICHMENT
This CVE record has been marked for NVD enrichment efforts.
Description
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops->syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock pointer. However, when the SMC listen socket is being closed concurrently, smc_close_active() sets clcsock->sk_user_data to NULL under sk_callback_lock, and then the smc_sock itself can be freed via sock_put() in smc_release(). This leads to two issues: 1) NULL pointer dereference: sk_user_data is NULL when accessed. 2) Use-after-free: sk_user_data is read as non-NULL, but the smc_sock is freed before its fields (e.g., queued_smc_hs, ori_af_ops) are accessed. The race window looks like this (the syzkaller crash [1] triggers via the SYN cookie path: tcp_get_cookie_sock() -> smc_tcp_syn_recv_sock(), but the normal tcp_check_req() path has the same race): CPU A (softirq) CPU B (process ctx) tcp_v4_rcv() TCP_NEW_SYN_RECV: sk = req->rsk_listener sock_hold(sk) /* No lock on listener */ smc_close_active(): write_lock_bh(cb_lock) sk_user_data = NULL write_unlock_bh(cb_lock) ... smc_clcsock_release() sock_put(smc->sk) x2 -> smc_sock freed! tcp_check_req() smc_tcp_syn_recv_sock(): smc = user_data(sk) -> NULL or dangling smc->queued_smc_hs -> crash! Note that the clcsock and smc_sock are two independent objects with separate refcounts. TCP stack holds a reference on the clcsock, which keeps it alive, but this does NOT prevent the smc_sock from being freed. Fix this by using RCU and refcount_inc_not_zero() to safely access smc_sock. Since smc_tcp_syn_recv_sock() is called in the TCP three-way handshake path, taking read_lock_bh on sk_callback_lock is too heavy and would not survive a SYN flood attack. Using rcu_read_lock() is much more lightweight. - Set SOCK_RCU_FREE on the SMC listen socket so that smc_sock freeing is deferred until after the RCU grace period. This guarantees the memory is still valid when accessed inside rcu_read_lock(). - Use rcu_read_lock() to protect reading sk_user_data. - Use refcount_inc_not_zero(&smc->sk.sk_refcnt) to pin the smc_sock. If the refcount has already reached zero (close path completed), it returns false and we bail out safely. Note: smc_hs_congested() has a similar lockless read of sk_user_data without rcu_read_lock(), but it only checks for NULL and accesses the global smc_hs_wq, never dereferencing any smc_sock field, so it is not affected. Reproducer was verified with mdelay injection and smc_run, the issue no longer occurs with this patch applied. [1] https://syzkaller.appspot.com/bug?extid=827ae2bfb3a3529333e9
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31632
|
|
31633
|
NVD - cve-2026-23450
nvd.nist.gov
Platform Team - NVD - cve-2026-23450
nvd.nist.gov
Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Open Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-23450 Detail
CVE-2026-23450
Detail
AWAITING ENRICHMENT
This CVE record has been marked for NVD enrichment efforts.
Description
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops->syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock pointer. However, when the SMC listen socket is being closed concurrently, smc_close_active() sets clcsock->sk_user_data to NULL under sk_callback_lock, and then the smc_sock itself can be freed via sock_put() in smc_release(). This leads to two issues: 1) NULL pointer dereference: sk_user_data is NULL when accessed. 2) Use-after-free: sk_user_data is read as non-NULL, but the smc_sock is freed before its fields (e.g., queued_smc_hs, ori_af_ops) are accessed. The race window looks like this (the syzkaller crash [1] triggers via the SYN cookie path: tcp_get_cookie_sock() -> smc_tcp_syn_recv_sock(), but the normal tcp_check_req() path has the same race): CPU A (softirq) CPU B (process ctx) tcp_v4_rcv() TCP_NEW_SYN_RECV: sk = req->rsk_listener sock_hold(sk) /* No lock on listener */ smc_close_active(): write_lock_bh(cb_lock) sk_user_data = NULL write_unlock_bh(cb_lock) ... smc_clcsock_release() sock_put(smc->sk) x2 -> smc_sock freed! tcp_check_req() smc_tcp_syn_recv_sock(): smc = user_data(sk) -> NULL or dangling smc->queued_smc_hs -> crash! Note that the clcsock and smc_sock are two independent objects with separate refcounts. TCP stack holds a reference on the clcsock, which keeps it alive, but this does NOT prevent the smc_sock from being freed. Fix this by using RCU and refcount_inc_not_zero() to safely access smc_sock. Since smc_tcp_syn_recv_sock() is called in the TCP three-way handshake path, taking read_lock_bh on sk_callback_lock is too heavy and would not survive a SYN flood attack. Using rcu_read_lock() is much more lightweight. - Set SOCK_RCU_FREE on the SMC listen socket so that smc_sock freeing is deferred until after the RCU grace period. This guarantees the memory is still valid when accessed inside rcu_read_lock(). - Use rcu_read_lock() to protect reading sk_user_data. - Use refcount_inc_not_zero(&smc->sk.sk_refcnt) to pin the smc_sock. If the refcount has already reached zero (close path completed), it returns false and we bail out safely. Note: smc_hs_congested() has a similar lockless read of sk_user_data without rcu_read_lock(), but it only checks for NULL and accesses the global smc_hs_wq, never dereferencing any smc_sock field, so it is not affected. Reproducer was verified with mdelay injection and smc_run, the issue no longer occurs with this patch applied. [1] https://syzkaller.appspot.com/bug?extid=827ae2bfb3a3529333e9
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
kernel.org
Base Score:
9.8 CRITICAL
9.8 CRITICAL
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
kernel.org
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
kernel.org
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
kernel.org
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
kernel.org
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
kernel.org
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
kernel.org
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
kernel.org...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31633
|
|
31634
|
NVD - cve-2026-23450
nvd.nist.gov
Platform Team - NVD - cve-2026-23450
nvd.nist.gov
Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Low vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
Medium vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
High vulnerabilities identified in packages are addressed (GitHub Repo) - Vanta
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Open Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-23450 Detail
CVE-2026-23450
Detail
AWAITING ENRICHMENT
This CVE record has been marked for NVD enrichment efforts.
Description
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops->syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock pointer. However, when the SMC listen socket is being closed concurrently, smc_close_active() sets clcsock->sk_user_data to NULL under sk_callback_lock, and then the smc_sock itself can be freed via sock_put() in smc_release(). This leads to two issues: 1) NULL pointer dereference: sk_user_data is NULL when accessed. 2) Use-after-free: sk_user_data is read as non-NULL, but the smc_sock is freed before its fields (e.g., queued_smc_hs, ori_af_ops) are accessed. The race window looks like this (the syzkaller crash [1] triggers via the SYN cookie path: tcp_get_cookie_sock() -> smc_tcp_syn_recv_sock(), but the normal tcp_check_req() path has the same race): CPU A (softirq) CPU B (process ctx) tcp_v4_rcv() TCP_NEW_SYN_RECV: sk = req->rsk_listener sock_hold(sk) /* No lock on listener */ smc_close_active(): write_lock_bh(cb_lock) sk_user_data = NULL write_unlock_bh(cb_lock) ... smc_clcsock_release() sock_put(smc->sk) x2 -> smc_sock freed! tcp_check_req() smc_tcp_syn_recv_sock(): smc = user_data(sk) -> NULL or dangling smc->queued_smc_hs -> crash! Note that the clcsock and smc_sock are two independent objects with separate refcounts. TCP stack holds a reference on the clcsock, which keeps it alive, but this does NOT prevent the smc_sock from being freed. Fix this by using RCU and refcount_inc_not_zero() to safely access smc_sock. Since smc_tcp_syn_recv_sock() is called in the TCP three-way handshake path, taking read_lock_bh on sk_callback_lock is too heavy and would not survive a SYN flood attack. Using rcu_read_lock() is much more lightweight. - Set SOCK_RCU_FREE on the SMC listen socket so that smc_sock freeing is deferred until after the RCU grace period. This guarantees the memory is still valid when accessed inside rcu_read_lock(). - Use rcu_read_lock() to protect reading sk_user_data. - Use refcount_inc_not_zero(&smc->sk.sk_refcnt) to pin the smc_sock. If the refcount has already reached zero (close path completed), it returns false and we bail out safely. Note: smc_hs_congested() has a similar lockless read of sk_user_data without rcu_read_lock(), but it only checks for NULL and accesses the global smc_hs_wq, never dereferencing any smc_sock field, so it is not affected. Reproducer was verified with mdelay injection and smc_run, the issue no longer occurs with this patch applied. [1] https://syzkaller.appspot.com/bug?extid=827ae2bfb3a3529333e9
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
kernel.org
Base Score:
9.8 CRITICAL
9.8 CRITICAL
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
kernel.org
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
kernel.org
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
kernel.org
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
kernel.org
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
kernel.org
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
kernel.org
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31634
|
|
31663
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Open Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-23450 Detail
CVE-2026-23450
Detail
AWAITING ENRICHMENT
This CVE record has been marked for NVD enrichment efforts.
Description
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops->syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock pointer. However, when the SMC listen socket is being closed concurrently, smc_close_active() sets clcsock->sk_user_data to NULL under sk_callback_lock, and then the smc_sock itself can be freed via sock_put() in smc_release(). This leads to two issues: 1) NULL pointer dereference: sk_user_data is NULL when accessed. 2) Use-after-free: sk_user_data is read as non-NULL, but the smc_sock is freed before its fields (e.g., queued_smc_hs, ori_af_ops) are accessed. The race window looks like this (the syzkaller crash [1] triggers via the SYN cookie path: tcp_get_cookie_sock() -> smc_tcp_syn_recv_sock(), but the normal tcp_check_req() path has the same race): CPU A (softirq) CPU B (process ctx) tcp_v4_rcv() TCP_NEW_SYN_RECV: sk = req->rsk_listener sock_hold(sk) /* No lock on listener */ smc_close_active(): write_lock_bh(cb_lock) sk_user_data = NULL write_unlock_bh(cb_lock) ... smc_clcsock_release() sock_put(smc->sk) x2 -> smc_sock freed! tcp_check_req() smc_tcp_syn_recv_sock(): smc = user_data(sk) -> NULL or dangling smc->queued_smc_hs -> crash! Note that the clcsock and smc_sock are two independent objects with separate refcounts. TCP stack holds a reference on the clcsock, which keeps it alive, but this does NOT prevent the smc_sock from being freed. Fix this by using RCU and refcount_inc_not_zero() to safely access smc_sock. Since smc_tcp_syn_recv_sock() is called in the TCP three-way handshake path, taking read_lock_bh on sk_callback_lock is too heavy and would not survive a SYN flood attack. Using rcu_read_lock() is much more lightweight. - Set SOCK_RCU_FREE on the SMC listen socket so that smc_sock freeing is deferred until after the RCU grace period. This guarantees the memory is still valid when accessed inside rcu_read_lock(). - Use rcu_read_lock() to protect reading sk_user_data. - Use refcount_inc_not_zero(&smc->sk.sk_refcnt) to pin the smc_sock. If the refcount has already reached zero (close path completed), it returns false and we bail out safely. Note: smc_hs_congested() has a similar lockless read of sk_user_data without rcu_read_lock(), but it only checks for NULL and accesses the global smc_hs_wq, never dereferencing any smc_sock field, so it is not affected. Reproducer was verified with mdelay injection and smc_run, the issue no longer occurs with this patch applied. [1] https://syzkaller.appspot.com/bug?extid=827ae2bfb3a3529333e9
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
kernel.org
Base Score:
9.8 CRITICAL
9.8 CRITICAL
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to
[EMAIL]
[EMAIL]
.
URL
Source(s)
Tag(s)
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
kernel.org
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
kernel.org
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
kernel.org
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
kernel.org
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
kernel.org
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
kernel.org
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
kernel.org
URL
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31663
|
|
31664
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31664
|
|
31665
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31665
|
|
31666
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New chat
Gemini
PRO
PRO
Conversation with Gemini
Conversation with Gemini
Hi Lukas
Where should we start?
Where should we start?
🖼️ Create image, button, tap to use tool
🖼️ Create image
🎸 Create music, button, tap to use tool
🎸 Create music
Help me learn, button, tap to use tool
Help me learn
Write anything, button, tap to use tool
Write anything
Boost my day, button, tap to use tool
Boost my day
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Fast
Microphone
Send message
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-23450 Detail
CVE-2026-23450
Detail
AWAITING ENRICHMENT
This CVE record has been marked for NVD enrichment efforts.
Description
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops->syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock pointer. However, when the SMC listen socket is being closed concurrently, smc_close_active() sets clcsock->sk_user_data to NULL under sk_callback_lock, and then the smc_sock itself can be freed via sock_put() in smc_release(). This leads to two issues: 1) NULL pointer dereference: sk_user_data is NULL when accessed. 2) Use-after-free: sk_user_data is read as non-NULL, but the smc_sock is freed before its fields (e.g., queued_smc_hs, ori_af_ops) are accessed. The race window looks like this (the syzkaller crash [1] triggers via the SYN cookie path: tcp_get_cookie_sock() -> smc_tcp_syn_recv_sock(), but the normal tcp_check_req() path has the same race): CPU A (softirq) CPU B (process ctx) tcp_v4_rcv() TCP_NEW_SYN_RECV: sk = req->rsk_listener sock_hold(sk) /* No lock on listener */ smc_close_active(): write_lock_bh(cb_lock) sk_user_data = NULL write_unlock_bh(cb_lock) ... smc_clcsock_release() sock_put(smc->sk) x2 -> smc_sock freed! tcp_check_req() smc_tcp_syn_recv_sock(): smc = user_data(sk) -> NULL or dangling smc->queued_smc_hs -> crash! Note that the clcsock and smc_sock are two independent objects with separate refcounts. TCP stack holds a reference on the clcsock, which keeps it alive, but this does NOT prevent the smc_sock from being freed. Fix this by using RCU and refcount_inc_not_zero() to safely access smc_sock. Since smc_tcp_syn_recv_sock() is called in the TCP three-way handshake path, taking read_lock_bh on sk_callback_lock is too heavy and would not survive a SYN flood attack. Using rcu_read_lock() is much more lightweight. - Set SOCK_RCU_FREE on the SMC listen socket so that smc_sock freeing is deferred until after the RCU grace period. This guarantees the memory is still valid when accessed inside rcu_read_lock(). - Use rcu_read_lock() to protect reading sk_user_data. - Use refcount_inc_not_zero(&smc->sk.sk_refcnt) to pin the smc_sock. If the refcount has already reached zero (close path completed), it returns false and we bail out safely. Note: smc_hs_congested() has a similar lockless read of sk_user_data without rcu_read_lock(), but it only checks for NULL and accesses the global smc_hs_wq, never dereferencing any smc_sock field, so it is not affected. Reproducer was verified with mdelay injection and smc_run, the issue no longer occurs with this patch applied. [1] https://syzkaller.appspot.com/bug?extid=827ae2bfb3a3529333e9
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31666
|
|
31667
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New chat
Gemini
PRO
PRO
Conversation with Gemini
Conversation with Gemini
Copy prompt
Edit
You said exaplin what is this and what shoud be done
You said
exaplin what is this and what shoud be done
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Fast
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Gemini is typing
Summarize page
Summarize page...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31667
|
|
31668
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
Edit
You said exaplin what is this and what shoud be done
You said
exaplin what is this and what shoud be done
Gemini said
Gemini said
It looks like you might have forgotten to attach a photo,
paste a snippet of code,
or describe the specific situation you're looking at!
Since I don't have the context yet,
I can't give you a definitive answer.
However,
if you provide more details,
here is how I can help:
If it's a tech/error message:
Paste the code or the error string.
I can break down what’s "breaking" and give you the fix.
If it's an image of an object or plant:
Upload the photo!
I can identify it and tell you how to handle or care for it.
If it's a document or a bill:
Describe the headers or the confusing parts,
and I’ll help you figure out the "fine print" and your next steps.
If it's a math or science problem:
Give me the equation (e.
g.,
),
and I’ll walk you through the solution.
What should you do now?
Just reply with a description,
an image,
or a copy-paste of whatever "this" is,
and I'll get to work.
What exactly are you looking at right now?
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Fast
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31668
|
|
31669
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
Edit
You said exaplin what is this and what shoud be done
You said
exaplin what is this and what shoud be done
Gemini said
Gemini said
It looks like you might have forgotten to attach a photo,
paste a snippet of code,
or describe the specific situation you're looking at!
Since I don't have the context yet,
I can't give you a definitive answer.
However,
if you provide more details,
here is how I can help:
If it's a tech/error message:
Paste the code or the error string.
I can break down what’s "breaking" and give you the fix.
If it's an image of an object or plant:
Upload the photo!
I can identify it and tell you how to handle or care for it.
If it's a document or a bill:
Describe the headers or the confusing parts,
and I’ll help you figure out the "fine print" and your next steps.
If it's a math or science problem:
Give me the equation (e.
g.,
),
and I’ll walk you through the solution.
What should you do now?
Just reply with a description,
an image,
or a copy-paste of whatever "this" is,
and I'll get to work.
What exactly are you looking at right now?
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Fast
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31669
|
|
31670
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
Edit
You said I’m on page “<tabTitle>NVD - cve-2026-23450</tabTitle>” with “<selection>References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4 kernel.org https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd kernel.org https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538 kernel.org https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023 kernel.org https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3 kernel.org https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275 kernel.org https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2 kernel.org Change History 3 change records found show changes</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-23450</tabTitle>” with “<selection>References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
kernel.org
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
kernel.org
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
kernel.org
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
kernel.org
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
kernel.org
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
kernel.org
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
kernel.org
Change History
3 change records found show changes</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Gemini said
Gemini said
Summary of NVD CVE-2026-23450 References
Summary of NVD CVE-2026-23450 References
The selected text provides external references and official disclaimers regarding the vulnerability
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Fast
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Gemini replied
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31670
|
|
31671
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
WORK, Google Account: [EMAIL]
Main menu
New Chat
Open menu for conversation actions.
Conversation with Gemini
Conversation with Gemini
Copy prompt
Edit
You said I’m on page “<tabTitle>NVD - cve-2026-23450</tabTitle>” with “<selection>References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [EMAIL]. URL Source(s) Tag(s) https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4 kernel.org https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd kernel.org https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538 kernel.org https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023 kernel.org https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3 kernel.org https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275 kernel.org https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2 kernel.org Change History 3 change records found show changes</selection>” selected. Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
You said
I’m on page “<tabTitle>NVD - cve-2026-23450</tabTitle>” with “<selection>References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [EMAIL].
URL
Source(s)
Tag(s)
https://git.kernel.org/stable/c/1e4f873879e075bbd4eb1c644d6933303ac5eba4
kernel.org
https://git.kernel.org/stable/c/1fab5ece76fb42a761178dcd0ebcbf578377b0dd
kernel.org
https://git.kernel.org/stable/c/6d5e4538364b9ceb1ac2941a4deb86650afb3538
kernel.org
https://git.kernel.org/stable/c/cadf3da46c15523fba90d80c9955f536ee3b4023
kernel.org
https://git.kernel.org/stable/c/f00fc26c8a06442b225a350fe000c0a11483e6a3
kernel.org
https://git.kernel.org/stable/c/f315277856caeafcd996c2611afc085ca2d53275
kernel.org
https://git.kernel.org/stable/c/fd7579f0a2c84ba8a7d4f206201b50dc8ddf90c2
kernel.org
Change History
3 change records found show changes</selection>” selected.
Please summarize the selection using precise and concise language. Use headers and bulleted lists in the summary, to make it scannable. Maintain the meaning and factual accuracy.
Expand
Gemini said
Gemini said
Summary of NVD CVE-2026-23450 References
Summary of NVD CVE-2026-23450 References
The selected text provides external references and official disclaimers regarding the vulnerability
Enter a prompt for Gemini
encrypted
Enter a prompt for Gemini
encrypted
Open upload file menu
Tools
Open mode picker
Fast
Stop response
Your Jiminny chats aren’t used to improve our models. Gemini is AI. It can make mistakes, so double check it.
Your privacy & Gemini Opens in a new window
Your privacy & Gemini
Opens in a new window
Gemini replied
Summarize page
Summarize page
An official website of the United States government...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31671
|
|
31672
|
Platform Team - Backlog - Jira
Platform Team - Bac Platform Team - Backlog - Jira
Platform Team - Backlog - Jira
[JY-19958] Upgrade BE libraries - May - Jira
[JY-19958] Upgrade BE libraries - May - Jira
jiminny/app/backend-code - Vanta
jiminny/app/backend-code - Vanta
NVD - cve-2026-23450
NVD - cve-2026-23450
Close tab
[JY-20773] User Pilot not receiving events on report generated - Jira
[JY-20773] User Pilot not receiving events on report generated - Jira
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
JY-19957 | Remove abanded sympfony debug, compose upgrade by nikolaybiaivanov · Pull Request #12022 · jiminny/app
Project Phoenix – Figma
Project Phoenix – Figma
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
TypeError: League\Flysystem\Filesystem::has(): Argument #1 ($location) must be of type string, null given, called in /home/jiminny/vendor/laravel/framework/src/Illuminate/Filesystem/FilesystemAdapter.php on line 218 — jiminny — app
New Tab
New Tab
Userpilot | Ask Jiminny Report Generated
Userpilot | Ask Jiminny Report Generated
[SRD-6848] Sidekick SMS issue - Jira
[SRD-6848] Sidekick SMS issue - Jira
New Tab
Customize sidebar
Close Google Gemini (⌃X)
Tabs from other devices
Open history (⇧⌘H)
Open bookmarks (⌘B)
AI Chat settings
Close
Gemini 3
Fast Answers quickly
Fast
Answers quickly
Thinking Solves complex problems
Thinking
Solves complex problems
Pro Advanced math and code with 3.1 Pro
Pro
Advanced math and code with 3.1 Pro
Get more from Gemini
Get our most capable models & features
Upgrade
Upgrade
Upgrade
Summarize page
Summarize page
An official website of the United States government
Here's how you know
Here's how you know
National Institute of Standards and Technology
NVD MENU
NVD
MENU
Information Technology Laboratory
Information Technology Laboratory
Information Technology Laboratory
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
NATIONAL VULNERABILITY DATABASE
VULNERABILITIES
VULNERABILITIES
CVE-2026-23450 Detail
CVE-2026-23450
Detail
AWAITING ENRICHMENT
This CVE record has been marked for NVD enrichment efforts.
Description
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops->syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock pointer. However, when the SMC listen socket is being closed concurrently, smc_close_active() sets clcsock->sk_user_data to NULL under sk_callback_lock, and then the smc_sock itself can be freed via sock_put() in smc_release(). This leads to two issues: 1) NULL pointer dereference: sk_user_data is NULL when accessed. 2) Use-after-free: sk_user_data is read as non-NULL, but the smc_sock is freed before its fields (e.g., queued_smc_hs, ori_af_ops) are accessed. The race window looks like this (the syzkaller crash [1] triggers via the SYN cookie path: tcp_get_cookie_sock() -> smc_tcp_syn_recv_sock(), but the normal tcp_check_req() path has the same race): CPU A (softirq) CPU B (process ctx) tcp_v4_rcv() TCP_NEW_SYN_RECV: sk = req->rsk_listener sock_hold(sk) /* No lock on listener */ smc_close_active(): write_lock_bh(cb_lock) sk_user_data = NULL write_unlock_bh(cb_lock) ... smc_clcsock_release() sock_put(smc->sk) x2 -> smc_sock freed! tcp_check_req() smc_tcp_syn_recv_sock(): smc = user_data(sk) -> NULL or dangling smc->queued_smc_hs -> crash! Note that the clcsock and smc_sock are two independent objects with separate refcounts. TCP stack holds a reference on the clcsock, which keeps it alive, but this does NOT prevent the smc_sock from being freed. Fix this by using RCU and refcount_inc_not_zero() to safely access smc_sock. Since smc_tcp_syn_recv_sock() is called in the TCP three-way handshake path, taking read_lock_bh on sk_callback_lock is too heavy and would not survive a SYN flood attack. Using rcu_read_lock() is much more lightweight. - Set SOCK_RCU_FREE on the SMC listen socket so that smc_sock freeing is deferred until after the RCU grace period. This guarantees the memory is still valid when accessed inside rcu_read_lock(). - Use rcu_read_lock() to protect reading sk_user_data. - Use refcount_inc_not_zero(&smc->sk.sk_refcnt) to pin the smc_sock. If the refcount has already reached zero (close path completed), it returns false and we bail out safely. Note: smc_hs_congested() has a similar lockless read of sk_user_data without rcu_read_lock(), but it only checks for NULL and accesses the global smc_hs_wq, never dereferencing any smc_sock field, so it is not affected. Reproducer was verified with mdelay injection and smc_run, the issue no longer occurs with this patch applied. [1] https://syzkaller.appspot.com/bug?extid=827ae2bfb3a3529333e9
Metrics
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST:
NVD
Base Score:
N/A
NVD assessment not yet provided.
CNA:
kernel.org
Base Score:
9.8 CRITICAL
9.8 CRITICAL
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to...
|
Firefox
|
NVD - cve-2026-23450 — Work
|
nvd.nist.gov/vuln/detail/cve-2026-23450
|
31672
|