PT-2026-31818 · Unknown · Phpsessionrestore

Seunghyun Yoon

+2

·

Published

2026-04-09

·

Updated

2026-04-30

·

CVE-2026-5507

CVSS v4.0

4.1

Medium

VectorAV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions versions prior to 2.3
Description When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the cache and for the application to call specific session restore APIs.
Recommendations Update to version 2.3 or later.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-5507

Affected Products

Phpsessionrestore