Vulnerability DatabaseGHSA-qf36-fx9f-232x

GHSA-qf36-fx9f-232x
PHP vulnerability analysis and mitigation

Overview

A critical SQL injection vulnerability was identified in ZendFramework (versions 1.10.0-1.10.9 and 1.11.0-1.11.6) when using PDO_MySQL with non-ASCII-compatible encodings. The vulnerability, tracked as GHSA-qf36-fx9f-232x, affects developers using non-ASCII-compatible encodings in conjunction with the MySQL PDO driver of PHP, while those using ASCII-compatible encodings like UTF8 or latin1 are not affected (Zend Advisory).

Technical details

The vulnerability stems from the PDO MySQL driver's inability to properly handle character set information in versions prior to PHP 5.3.6. The issue specifically affects PDO's quoting mechanisms when used with non-ASCII compatible encodings. The vulnerability has been assigned a CVSS v3.1 score of 9.8 (Critical), with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating high severity impacts on confidentiality, integrity, and availability with network-based attack vectors requiring no privileges or user interaction (GitHub Advisory).

Impact

When exploited, this vulnerability could lead to SQL injection attacks in applications using non-ASCII compatible encodings with PDO MySQL. The impact is particularly severe as it affects PDO's quoting mechanisms and emulated prepared statements, potentially allowing unauthorized access to or modification of database contents (Zend Advisory).

Exploitability

The vulnerability can be exploited when using non-ASCII-compatible encodings such as GBK with PDO MySQL. A proof of concept demonstrated that using PDO::quote() with specific character sequences could bypass SQL injection protections, potentially exposing all tables on the server (PHP Bug).

Mitigation and workarounds

The vulnerability was patched in Zend Framework versions 1.10.9 and 1.11.6. The fix ensures that charset information provided to the PDO MySQL adapter is sent both as part of the DSN and in a SET NAMES query. Users are strongly recommended to upgrade to PHP 5.3.6 or later and use Zend Framework version 1.11.6 or greater, or 1.10.9 if using the 1.10 series (Zend Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59989CRITICAL9.2
  • PHP logoPHP
  • phalcon/cphalcon
NoYesAug 21, 2026
CVE-2026-63135HIGH8.2
  • PHP logoPHP
  • yourls/yourls
NoYesAug 21, 2026
GHSA-p2ch-c2c3-4xm5MEDIUM6.1
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-8hgv-xc77-jmcrMEDIUM5.1
  • PHP logoPHP
  • getgrav/grav
NoYesAug 21, 2026
GHSA-hq84-x37p-j6q5MEDIUM4.5
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management