PatchSiren

james-heinrich CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH james-heinrich CVE published 2026-09-20

CVE-2026-94108

CVE-2026-94108 is an XML external entity injection vulnerability in the getID3 library through version 1.9.26. The vulnerability exists in the XML2array helper function, which fails to properly disable entity loading in PHP versions before 8.0. This allows attackers to craft malicious XML metadata in media files to potentially disclose local files, perform server-side request forgery, or cause denial of s [truncated]