Vulnerability DatabaseGHSA-vjrg-wpm8-rhrw

GHSA-vjrg-wpm8-rhrw
PHP vulnerability analysis and mitigation

Overview

A regression vulnerability was identified in doctrine/orm versions 2.8.3 affecting the query builder functionality. The issue, tracked as GHSA-vjrg-wpm8-rhrw, was discovered in April 2021 and involves improper handling of case-insensitive checks in SQL query parentheses. The vulnerability affects doctrine/orm versions greater than or equal to 2.8.3 and less than 2.8.4 (GitHub Advisory).

Technical details

The vulnerability stems from a regression where statements in Where-Clause were not properly wrapped in brackets due to improper handling of case-insensitive checks. Specifically, when using lowercase 'or' or 'and' operators in queries like ->andWhere("u.name = ?1 or u.username = ?1"), the query builder failed to wrap the conditions in parentheses, while it still worked correctly for uppercase 'OR' and 'AND' operators (Doctrine PR).

Impact

The improper handling of parentheses in SQL queries could potentially lead to incorrect query execution and unexpected results when using case-insensitive logical operators in where clauses. This could affect applications relying on specific query logic implementation (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in version 2.8.4 of doctrine/orm. Users are advised to upgrade to this version or later to resolve the issue (GitHub Advisory).

Community reactions

The issue was initially reported through GitHub and was quickly addressed by the Doctrine team. The development team acknowledged that the issue was missed due to insufficient test coverage, particularly noting that some test cases were not properly suffixed with 'Test' and thus were not executed during routine testing (Doctrine PR).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47156CRITICAL9.3
  • PHP logoPHP
  • mantisbt/mantisbt
NoYesSep 09, 2026
CVE-2026-85400HIGH7.5
  • PHP logoPHP
  • cpe:2.3:a:typo3:typo3
NoYesSep 08, 2026
CVE-2026-53637MEDIUM6.5
  • PHP logoPHP
  • sylius/sylius
NoYesSep 08, 2026
CVE-2026-53639MEDIUM6.3
  • PHP logoPHP
  • sylius/sylius
NoYesSep 08, 2026
CVE-2026-53638MEDIUM4.3
  • PHP logoPHP
  • sylius/sylius
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management