Vulnerability DatabaseGHSA-gm98-g2wf-7c68

GHSA-gm98-g2wf-7c68
PHP vulnerability analysis and mitigation

Overview

A cookie handling vulnerability was discovered in amphp/artax versions before 1.0.6 and 2 before 2.0.6. The vulnerability allowed cookies from subdomains (e.g., foo.bar.example.com) to be leaked to parent domains (e.g., foo.bar). Additionally, any site could set cookies for any other site, creating potential security risks (GitHub Advisory).

Technical details

The vulnerability stemmed from improper cookie domain validation and handling. The issue specifically affected how the application managed cookie domains and their boundaries. The fix implemented stricter cookie handling rules following modern browser implementations, where cookies can only be set on domains higher or equal to the current domain, while preventing setting on public suffixes (Artax Release).

Impact

The vulnerability could allow malicious websites to set cookies for other domains and potentially lead to cookie leakage across domain boundaries. This could result in unauthorized access to user sessions or information intended to be restricted to specific subdomains (GitHub Advisory).

Exploitability

The vulnerability was rated as Moderate severity. It could be exploited by manipulating cookie domains and taking advantage of the loose domain validation in the affected versions (GitHub Advisory).

Mitigation and workarounds

The vulnerability was fixed in versions 1.0.6 and 2.0.6. The fix implemented proper cookie domain validation following modern browser implementations, preventing cookie leakage to wrong origins and restricting cookie acceptance criteria. Users should upgrade to these patched versions to mitigate the vulnerability (GitHub Advisory, Artax Release).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44741HIGH8.8
  • PHP logoPHP
  • pimcore/admin-ui-classic-bundle
NoYesAug 12, 2026
CVE-2026-47233MEDIUM6.5
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-47132MEDIUM5.4
  • PHP logoPHP
  • thorsten/phpmyfaq
NoYesAug 12, 2026
CVE-2026-47234MEDIUM4.4
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-49262LOW3
  • PHP logoPHP
  • aimeos/pagible
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management