Register for the AI for Security Summit: Join Figma, Perplexity & Wiz
Vulnerability DatabaseGHSA-hhw9-35p2-q2c5

GHSA-hhw9-35p2-q2c5
PHP vulnerability analysis and mitigation

Overview

The Steam Socialite Provider version 1.x contains a critical security vulnerability identified as GHSA-hhw9-35p2-q2c5, discovered and disclosed on January 29, 2021. The vulnerability affects the socialiteproviders/steam Composer package versions below 1.1. This security issue impacts the OpenID authentication implementation for Laravel Socialite when integrating with Steam authentication (GitHub Advisory).

Technical details

The vulnerability is classified as Critical severity and is identified with CWE-346. The core issue lies in the improper validation of OpenID server authentication, where version 1 of the Steam Socialite Provider fails to properly verify if the login originates from steamcommunity.com (GitHub Advisory).

Impact

The vulnerability allows malicious actors to substitute their own OpenID server during the authentication process, potentially compromising the authentication mechanism. This could lead to unauthorized access and potential impersonation of Steam users within applications using the affected package (GitHub Advisory).

Exploitability

The vulnerability enables attackers to perform authorization domain spoofing. Without proper host validation, fraudsters could potentially gain unauthorized access to the application under other users' credentials (Packagist).

Mitigation and workarounds

Users are strongly advised to upgrade to version 3 or 4 of the package, which implements a hardcoded endpoint to verify the login. The newer versions also include additional security features such as the 'allowed_hosts' configuration option to protect against authorization domain spoofing (GitHub Advisory, Packagist).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71537MEDIUM6.5
  • PHP logoPHP
  • paymenter/paymenter
NoYesSep 18, 2026
CVE-2026-77616MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77610MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77609MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77608MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management