CVE-2026-33942: Php Unserialize Allowed Classes True
Call to PHP unserialize() with allowed_classes => true (or without a restrictive allowed_classes option) permits instantiation of arbitrary classes loaded by the application. If the serialized input is not fully under developer control (e.g., comes from a cache, file, database, HTTP input, or any storage backend an attacker could tamper with), this leads to
greprules fetch cve-2026-33942-php-unserialize-allowed-classes-true --engine opengrepDescription
Call to PHP unserialize() with allowed_classes => true (or without a restrictive allowed_classes option) permits instantiation of arbitrary classes loaded by the application. If the serialized input is not fully under developer control (e.g., comes from a cache, file, database, HTTP input, or any storage backend an attacker could tamper with), this leads to
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.