CVE-2026-7317: Unsafe Unserialize Missing Hmac
Unsafe deserialization of data from files, streams, or decoded strings without integrity checks. An attacker who can control the input can inject arbitrary PHP objects, leading to Remote Code Execution. Ensure data is cryptographically signed (e.g., using HMAC) and verified with `hash_equals` before calling `unserialize`.
greprules fetch cve-2026-7317-unsafe-unserialize-missing-hmac --engine opengrepDescription
Unsafe deserialization of data from files, streams, or decoded strings without integrity checks. An attacker who can control the input can inject arbitrary PHP objects, leading to Remote Code Execution. Ensure data is cryptographically signed (e.g., using HMAC) and verified with `hash_equals` before calling `unserialize`.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.