CVE-2026-24765

unknown
Published 2026-01-27 · Modified 2026-05-05
CVSS v3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk

Description

PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-24765

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyefixed9.5.2-1+deb11u1
debian debianforkyfixed12.5.8-1
debian debiansidfixed12.5.8-1
debian debiantrixiefixed11.5.19-1+deb13u1

Package impact

EcosystemPackageVulnerableFixed
php Packagistphpunit/phpunit<8.5.528.5.52
php Packagistphpunit/phpunit>=9.0.0,<9.6.339.6.33
php Packagistphpunit/phpunit>=10.0.0,<10.5.6210.5.62
php Packagistphpunit/phpunit>=11.0.0,<11.5.5011.5.50
php Packagistphpunit/phpunit>=12.0.0,<12.5.812.5.8

References

Verify integrity in audit chain (admin only). AS-IS.