CVE-2022-31628

MEDIUM5.5EPSS 0.01%

phar wrapper can occur dos when using quine gzip file

Published: 9/28/2022Modified: 4/28/2026

Description

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References (10)