Back

MEDIUM

Filter bypass in filter_var (FILTER_VALIDATE_URL)

Published Jun 9, 2024

Description

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.

Affected products

Remediation

Red Hat statement

This flaw in PHP's filter_var function with FILTER_VALIDATE_URL constitutes a moderate severity issue because, while it allows URLs with invalid user information to be treated as valid, it does not directly facilitate immediate security breaches or exploits on its own. The impact is limited to cases where applications rely solely on this function for URL validation without additional checks, potentially leading to improper handling of user credentials. However, the flaw does not compromise the overall integrity of the PHP interpreter, nor does it inherently lead to data corruption or system crashes. Its exploitation requires specific conditions and contexts, making it less critical than high-severity vulnerabilities that enable direct remote code execution or privilege escalation.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (12)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner php
Published Jun 9, 2024
Updated Nov 3, 2025
Reserved May 29, 2024

CISA Vulnrichment

Updated Jun 10, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Oct 21, 2022
Bugzilla 2291252

ENISA EUVD

Assigner php
Published Jun 9, 2024
Updated Nov 3, 2025

GitHub

No data