CVE-2026-31825: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-31825 is a DQL (Doctrine Query Language) injection vulnerability in the Sylius open-source eCommerce framework for Symfony. The ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter API filters pass user-supplied order direction values directly to Doctrine's orderBy() without validation, enabling unauthenticated attackers to inject arbitrary DQL. It affects all Sylius versions up to and including 2.2.2 across multiple release branches (1.9.x through 2.2.x). The vulnerability was disclosed on March 9, 2026, and carries a CVSS v3.1 base score of 5.3 (Moderate) (GitHub Advisory, Sylius Advisory).

Technical details

The root cause is improper neutralization of special elements in data query logic (CWE-943) and SQL/DQL injection (CWE-89). The vulnerable filters accept the order query parameter from API requests and pass the direction value (e.g., ASC or DESC) directly to Doctrine ORM's orderBy() method without whitelisting or sanitizing the input. An attacker can append additional DQL clauses to the direction value, as demonstrated by the proof-of-concept request: GET /api/v2/shop/products?order[price]=ASC,%20variant.code%20DESC. No authentication or special privileges are required — the attack is executable by any network-accessible client against the public-facing API endpoint (GitHub Advisory, Sylius Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to inject arbitrary DQL into database queries, potentially enabling unauthorized read access to sensitive data stored in the Sylius database, including product pricing, customer records, and other confidential eCommerce information. The CVSS assessment reflects a low confidentiality impact with no integrity or availability impact, meaning the primary risk is unauthorized data disclosure rather than data modification or service disruption. Lateral movement within the application is not directly facilitated, but exposed customer or payment data could enable downstream attacks (GitHub Advisory, Feedly).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.047% (15th percentile), indicating a low near-term exploitation probability. No threat actor attribution has been reported. The attack requires no authentication and low complexity, which lowers the barrier for exploitation if a PoC is published (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Sylius-based eCommerce sites running vulnerable versions (≤1.9.11, 1.10.0–1.10.15, 1.11.0–1.11.16, 1.12.0–1.12.22, 1.13.0–1.13.14, 1.14.0–1.14.17, 2.0.0–2.0.15, 2.1.0–2.1.11, 2.2.0–2.2.2) using tools like Shodan or by inspecting HTTP response headers for Sylius version indicators.
  2. Identify vulnerable API endpoint: Confirm the /api/v2/shop/products endpoint is accessible and accepts order query parameters.
  3. Craft malicious request: Construct a GET request that injects additional DQL into the order direction parameter, e.g., GET /api/v2/shop/products?order[price]=ASC,%20variant.code%20DESC or more complex DQL expressions to probe data exposure.
  4. Inject arbitrary DQL: Extend the payload to include DQL subqueries or expressions that extract sensitive data from related entities (e.g., customer emails, order details) by appending them to the direction value passed to orderBy().
  5. Exfiltrate data: Analyze API responses for data returned out of expected order or containing injected query results, iterating payloads to enumerate sensitive database contents (Sylius Advisory).

Indicators of compromise

  • Network: Unusual GET requests to /api/v2/shop/products or other API endpoints with order parameters containing URL-encoded spaces, commas, or additional field references beyond simple ASC/DESC values (e.g., order[price]=ASC%2C%20variant.code%20DESC).
  • Logs: Web server or application access logs showing API requests with malformed or unexpectedly long order[] query parameter values; repeated requests to product listing API endpoints with varying injection payloads from the same IP.
  • Application: Doctrine query logs (if enabled) showing ORDER BY clauses with unexpected additional columns or expressions not matching standard filter fields (Sylius Advisory).

Mitigation and workarounds

Upgrade Sylius to one of the patched versions: 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, 1.14.18, 2.0.16, 2.1.12, or 2.2.3 (Sylius Advisory). For installations that cannot be patched immediately, implement a Symfony EventSubscriber (SanitizeOrderDirectionSubscriber) that intercepts API requests and whitelists the order direction parameter to only ASC or DESC before it reaches the vulnerable filters. Register the subscriber scoped to the /api/v2 route prefix using %sylius.security.new_api_route%, then clear the Symfony cache with bin/console cache:clear. Additionally, deploying a WAF rule to reject order[] parameter values containing characters beyond alphanumeric and basic direction keywords provides an additional layer of defense (GitHub Advisory).

Community reactions

The vulnerability was responsibly disclosed by Chris Alupului (@Neosprings) and Bartłomiej Nowiński (@bnBart), who are credited in the official Sylius security advisory (Sylius Advisory). Sylius published a security blog post covering the issue for both version 1.x and 2.x branches (Sylius Blog). No significant broader media coverage or notable community controversy has been observed beyond standard vulnerability tracking.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management