PT-2026-31818 · Unknown · Phpsessionrestore
Seunghyun Yoon
+2
·
Published
2026-04-09
·
Updated
2026-04-30
·
CVE-2026-5507
CVSS v4.0
4.1
Medium
| Vector | AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
versions prior to 2.3
Description
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the cache and for the application to call specific session restore APIs.
Recommendations
Update to version 2.3 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpsessionrestore