phalcon/cphalcon Security Advisories (3)
-
[HIGH] Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS
PKSA-5stm-rfkw-zjbb CVE-2026-57584 GHSA-x7rj-f32v-7jjg
Affected version: <=5.14.2
Reported by:
GitHub -
[HIGH] Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel)
PKSA-65xj-m5g6-56k1 CVE-2026-54736 GHSA-8jqh-95g6-7jpj
Affected version: <=5.14.0
Reported by:
GitHub -
[CRITICAL] Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
PKSA-n2s8-x5tr-m78t CVE-2026-59989 GHSA-hrwp-4hh9-c8r8
Affected version: <=5.15.0
Reported by:
GitHub