PT-2026-31818 · Unknown · Phpsessionrestore

·

CVE-2026-5507

·

Published

2026-04-09

·

Updated

2026-07-14

CVSS v4.0

4.1

Medium

VectorAV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions versions prior to 2.3
Description When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the cache and for the application to call specific session restore APIs.
Recommendations Update to version 2.3 or later.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5507
JLSEC-2026-733

Affected Products

Phpsessionrestore