Security: validate nested stream wrapper in stream: resource (CWE-22) (#1195) The built-in stream: resource type let a template bypass Security stream restrictions. BasePlugin::load() matches the 'stream' sysplugin before the stream_get_wrappers()/isTrustedStream() check, so a resource such as stream:php://filter/read=convert.base64-encode/resource=/path was opened by StreamPlugin::getContent() via fopen() on the nested php:// wrapper without ever validating it. This bypassed Security::$streams (including Security::$streams = null) and allowed reading arbitrary local files. Parse the wrapper scheme from the resolved path in StreamPlugin::getContent() and validate it with Security::isTrustedStream() before fopen(), giving the stream: resource the same check the direct wrapper path already receives. Adds regression tests covering the disabled-streams bypass, the not-on-allowlist case, and a positive test that an explicitly allowed wrapper still works.
Items tagged: @php (15)
Recent Commits to smarty:master
-
Security: validate nested stream wrapper in stream: resource (CWE-22)…
Recent Commits to Mobile-Detect
-
fix(cache): bound in-memory Cache to prevent unbounded growth (GHSA-m…
fix(cache): bound in-memory Cache to prevent unbounded growth (GHSA-mgj4-qjmw-v56v) The bundled Detection\Cache\Cache is now bounded by default (1000 entries, FIFO eviction). Prevents unbounded in-memory growth when one MobileDetect instance is reused across many distinct User-Agents in a long-running PHP runtime (RoadRunner, Laravel Octane, FrankenPHP worker mode, Swoole, ReactPHP, queue workers). Classic PHP-FPM / mod_php deployments are not affected (cache dies with the request). Custom PSR-16 adapters (Redis, APCu, Memcached, Filesystem) are unaffected; their eviction policy is the operator's responsibility. The README "Long-Running Processes" worker example now uses clear() instead of evictExpired() — the latter is a no-op against fresh entries under the default 86400s TTL and was misleading users into thinking it bounded the cache by cardinality. - Cache::__construct(int $maxEntries = Cache::DEFAULT_MAX_ENTRIES) - Cache::getMaxEntries() accessor - evictExpired() docblock clarified (bounds by TTL only, not cardinality) - Regression tests in CacheTest + MobileDetectWithCacheTest mirroring the advisory PoC - README-EXAMPLES.md "Long-Running Processes" rewritten - Version bumped to 4.11.0
Recent Commits to awesome-php:master
-
Remove 21 unmaintained/archived libraries (#1402)
Remove 21 unmaintained/archived libraries (#1402) * Remove 9 unmaintained libraries (no updates since 2016-2017) * Also remove 12 GitHub-archived repositories
-
Replace unmaintained yosymfony/toml with php-collective/toml (#1401)
Replace unmaintained yosymfony/toml with php-collective/toml (#1401) * Replace unmaintained yosymfony/toml with php-collective/toml
Recent Commits to simple-comment-editing:master
-
Adding abspath checks.
Adding abspath checks.
Recent Commits to smarty:master
-
Support for Laravel Collections style object chaining (#1168)
Support for Laravel Collections style object chaining (#1168) * Support for Laravel Collections style object chaining for objects return from function calls implemented as modifiers Fixes #1151 * explain publishing docs
Recent Commits to awesome-php:master
-
Add Djot parser to the list of Markdown parsers
Add Djot parser to the list of Markdown parsers
Recent Commits to documents
-
Ajustes para uso de CNPJ alfanumérico tanto no CNPJ como nas chaves d…
Ajustes para uso de CNPJ alfanumérico tanto no CNPJ como nas chaves dos documentos fiscais eletrônicos.
Recent Commits to policies:main
-
Merge pull request #10 from Crell/third-party-code
Merge pull request #10 from Crell/third-party-code Add a policy page on third party code usage.
Recent Commits to kint:master
-
Use more modern tricks
Use more modern tricks We've got a few new features between 7.1 and 7.4 so this is nice. Unfortunately we still have to use array_merge for arrays with string keys since that wasn't supported until 8.1
-
Parser: Improve TRIGGER_ mask definitions
Parser: Improve TRIGGER_ mask definitions
-
Utils::isValidPhpName
Utils::isValidPhpName
Recent Commits to Mobile-Detect
-
PHP 8.4 - implicit nulls are deprecated (#960)
PHP 8.4 - implicit nulls are deprecated (#960)
Recent Commits to policies:main
-
Implement the changes of the Release Cycle Update RFC (#5)
Implement the changes of the Release Cycle Update RFC (#5) RFC: https://wiki.php.net/rfc/release_cycle_update --------- Co-authored-by: Peter Kokot <peterkokot@gmail.com> Co-authored-by: Ben Ramsey <ben@benramsey.com> Co-authored-by: Sergey Panteleev <sergey@php.net>
Recent Commits to Search-Replace-DB:master
-
Fix unserialize() warnings, deprecated warnings.
Fix unserialize() warnings, deprecated warnings. As of PHP 8.3 unserialize() triggers E_WARNING instead of E_NOTICE causing SRDB to dump thousands of notices to the screen as it tries to unserialized non-serialized strings. It now checks for serialized data before trying to unserialize. Fixed Deprecation warning creating dynamic property: alter_collation. Fixed Deprecation warning when passing null to htmlentities().