Items tagged: @php (15)

Recent Commits to smarty:master

  • 29/06/2026 6:47

    Security: validate nested stream wrapper in stream: resource (CWE-22)…

    Security: validate nested stream wrapper in stream: resource (CWE-22) (#1195)
    
    The built-in stream: resource type let a template bypass Security stream
    restrictions. BasePlugin::load() matches the 'stream' sysplugin before the
    stream_get_wrappers()/isTrustedStream() check, so a resource such as
    stream:php://filter/read=convert.base64-encode/resource=/path was opened by
    StreamPlugin::getContent() via fopen() on the nested php:// wrapper without
    ever validating it. This bypassed Security::$streams (including
    Security::$streams = null) and allowed reading arbitrary local files.
    
    Parse the wrapper scheme from the resolved path in StreamPlugin::getContent()
    and validate it with Security::isTrustedStream() before fopen(), giving the
    stream: resource the same check the direct wrapper path already receives.
    
    Adds regression tests covering the disabled-streams bypass, the
    not-on-allowlist case, and a positive test that an explicitly allowed wrapper
    still works.
    Tags:

Recent Commits to Mobile-Detect

  • 24/05/2026 9:32

    fix(cache): bound in-memory Cache to prevent unbounded growth (GHSA-m…

    fix(cache): bound in-memory Cache to prevent unbounded growth (GHSA-mgj4-qjmw-v56v)
    
    The bundled Detection\Cache\Cache is now bounded by default (1000 entries,
    FIFO eviction). Prevents unbounded in-memory growth when one MobileDetect
    instance is reused across many distinct User-Agents in a long-running PHP
    runtime (RoadRunner, Laravel Octane, FrankenPHP worker mode, Swoole,
    ReactPHP, queue workers).
    
    Classic PHP-FPM / mod_php deployments are not affected (cache dies with
    the request). Custom PSR-16 adapters (Redis, APCu, Memcached, Filesystem)
    are unaffected; their eviction policy is the operator's responsibility.
    
    The README "Long-Running Processes" worker example now uses clear() instead
    of evictExpired() — the latter is a no-op against fresh entries under the
    default 86400s TTL and was misleading users into thinking it bounded the
    cache by cardinality.
    
    - Cache::__construct(int $maxEntries = Cache::DEFAULT_MAX_ENTRIES)
    - Cache::getMaxEntries() accessor
    - evictExpired() docblock clarified (bounds by TTL only, not cardinality)
    - Regression tests in CacheTest + MobileDetectWithCacheTest mirroring the
      advisory PoC
    - README-EXAMPLES.md "Long-Running Processes" rewritten
    - Version bumped to 4.11.0
    Tags:

Recent Commits to awesome-php:master

Recent Commits to simple-comment-editing:master

Recent Commits to smarty:master

Recent Commits to awesome-php:master

Recent Commits to documents

Recent Commits to policies:main

Recent Commits to kint:master

Recent Commits to Mobile-Detect

Recent Commits to policies:main

Recent Commits to Search-Replace-DB:master

  • 23/02/2024 15:50

    Fix unserialize() warnings, deprecated warnings.

    Fix unserialize() warnings, deprecated warnings.
    
    As of PHP 8.3 unserialize() triggers E_WARNING instead of E_NOTICE causing SRDB to dump thousands of notices to the screen as it tries to unserialized non-serialized strings. It now checks for serialized data before trying to unserialize.
    
    Fixed Deprecation warning creating dynamic property: alter_collation.
    
    Fixed Deprecation warning when passing null to htmlentities().
    Tags:

Log in