Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ch8v-r6jh-4vvr

Опубликовано: 24 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

ext/filter: encode 0xFF in FILTER_SANITIZE_ENCODED

Summary

php_filter_encode_url() builds a 256-entry lookup table that decides which bytes FILTER_SANITIZE_ENCODED percent-encodes, but initialises only the first 255 entries. Entry 255 is read uninitialised, so whether the byte 0xFF is encoded or passed through depends on whatever happened to be on the stack.

Details

The table is filled with memset(tmp, 1, sizeof(tmp) - 1), which leaves tmp[255] untouched:

https://github.com/php/php-src/blob/php-8.5.9/ext/filter/sanitizing_filters.c#L73

The filter then consults tmp[*s] for every input byte, so for 0xFF the decision comes from uninitialised stack memory. Every other byte is handled deterministically.

The fix changes the memset() length to sizeof(tmp) so the whole table is initialised.

PoC

<?php $out = filter_var("\xff\xfeabc", FILTER_SANITIZE_ENCODED); echo "in : ", bin2hex("\xff\xfeabc"), "\n"; echo "out: ", bin2hex($out), "\n";
in : fffe616263 out: ff254645616263

0xFE is percent-encoded as %FE while 0xFF is passed through raw, showing that tmp[255] was read uninitialised.

Impact

The impact is low. There is no crash and no memory corruption; the only effect is that the 0xFF byte is sanitised inconsistently, depending on uninitialised stack contents. A downstream consumer that relies on FILTER_SANITIZE_ENCODED producing fully percent-encoded output could in principle be affected as part of a longer chain, but the filter provides no such guarantee on its own.

This issue was fixed publicly in 8.4.25 and 8.5.10 before it was recognised as security relevant, and is backported here to the branches that receive security fixes only.

Пакеты

Наименование

php

php
Затронутые версииВерсия исправления

>=8.2.0, <8.2.34

8.2.34

Наименование

php

php
Затронутые версииВерсия исправления

>=8.3.0, <8.3.35

8.3.35

Наименование

php

php
Затронутые версииВерсия исправления

>=8.4.0, <8.4.25

8.4.25

Наименование

php

php
Затронутые версииВерсия исправления

>=8.5.0, <8.5.10

8.5.10

3.7 Low

CVSS3

3.7 Low

CVSS3