phalcon/cphalcon
Packagist3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting phalcon/cphalconpage 1 of 1
- CVE-2026-54736HIGHCVSS 8.2EG 8.2✓ Fixed in 5.14.12026-07-10
vulnerable: 5.10.0 ... v5.8.0 (94 versions)
Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HMAC using PHP/Zephir identity comparison, which lowers to a b…
- CVE-2026-57584HIGHCVSS 8.7EG 8.7✓ Fixed in 5.15.02026-07-10
vulnerable: 5.10.0 ... v5.8.0 (96 versions)
Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled PCRE pattern contains the nested quantifier (/.), and the same co…
- CVE-2026-59989CRITICALCVSS 9.2EG 9.2✓ Fixed in 5.16.02026-08-21
vulnerable: 5.10.0 ... v5.8.0 (97 versions)
Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the join filter by inserting the raw separator and array token values into generated PHP with…
Check whether phalcon/cphalcon is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for phalcon/cphalcon CVEs against the assets you own.
Start Free Scan →