Loading HuntDB...

GHSA-rxcr-7xjm-f9c9

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.

Related CVEs

Key Information

GHSA ID
GHSA-rxcr-7xjm-f9c9
Published
May 24, 2022 7:16 PM
Last Modified
September 30, 2022 12:00 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.