Skip to content

Backport security patches from 3.x and 4.x#799

Merged
markstory merged 4 commits into
2.xfrom
backport-796
Jun 25, 2026
Merged

Backport security patches from 3.x and 4.x#799
markstory merged 4 commits into
2.xfrom
backport-796

Conversation

@markstory

Copy link
Copy Markdown
Member

I forgot that 2.x was still getting support (until 4.x goes out of support).

Fixes #798

Backport of #795 to 3.x

Because of how browsers handle the `Location` header, values beginning
with `\` can be leveraged to create redirect targets on other domains.

Thanks to Volker Dusch and the PHP Ecosystem security team for reporting this.
The firebase/php-jwt package contains a vulnerability that can only be
resolved by going to 7.x. I didn't want to also change the requirements
of this package as part of the redirect fix.
@markstory markstory added this to the 2.x milestone Jun 24, 2026
@markstory

markstory commented Jun 24, 2026

Copy link
Copy Markdown
Member Author

@jiru I could use some help here, I don't have a compatible version of PHP installed right now.

Figured it out, I had a bad merge.

We don't want this much from 3.x
@markstory markstory merged commit 9aec999 into 2.x Jun 25, 2026
5 of 6 checks passed
@markstory markstory deleted the backport-796 branch June 25, 2026 03:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant