PatchSiren

Phalcon CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Phalcon CVE published 2026-08-21

CVE-2026-59989

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:17:00.713Z and has not been modified since then. Phalcon framework versions 5.15.0 and earlier contain a critical vulnerability (CVE-2026-59989) that allows for PHP injection and execution due to improper sanitization of user input in the resolveFilter function of the Volt compiler. An attacke [truncated]

HIGH phalcon CVE published 2026-07-10

CVE-2026-57584

CVE-2026-57584 is a high-severity vulnerability in the Phalcon PHP framework. The vulnerability occurs in the Phalcon MVC application's default router, which registers a built-in route with a compiled PCRE pattern containing a nested quantifier (/.). This pattern can be exploited by a crafted path to trigger catastrophic backtracking and cause CPU exhaustion or route-matching failure. The issue is fixed i [truncated]

HIGH phalcon CVE published 2026-07-10

CVE-2026-54736

The Phalcon framework's Crypt::decrypt method is vulnerable to a timing attack. An attacker can exploit this vulnerability to recover a valid HMAC tag byte-by-byte and attach it to a chosen IV and ciphertext, allowing decrypt() to accept tampered encrypted content as authentic. This issue affects Phalcon framework versions prior to 5.14.1. The vulnerability has a CVSS score of 8.2 and is classified as HIG [truncated]