| Server IP : 35.80.110.71 / Your IP : 216.73.216.221 Web Server : Apache/2.4.58 (Ubuntu) System : Linux ip-172-31-21-44 6.17.0-1019-aws #19~24.04.1-Ubuntu SMP Tue Jun 23 18:53:06 UTC 2026 x86_64 User : ubuntu ( 1000) PHP Version : 8.3.31 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : OFF | Sudo : ON | Pkexec : OFF Directory : /proc/2798582/cwd/scripts/ci/ |
Upload File : |
{
"_comment": "Plan 270 §Phase 7 — Acknowledged high/critical composer audit advisories. Each entry must carry an owner + target_date (YYYY-MM-DD) explaining when it will be cleared. The CI gate (scripts/ci/composer-audit-gate.php) blocks NEW high/critical advisories outside this list and warns on entries whose target_date has elapsed. Review monthly.",
"_review_cadence": "monthly",
"acknowledged": [
{
"advisoryId": "PKSA-3r5d-mb8f-1qw9",
"packageName": "laravel/framework",
"severity": "high",
"title": "CRLF injection in default email rule",
"owner": "ops",
"target_date": "2026-08-01",
"notes": "Upgrade laravel/framework to the patched 12.x line. Wait for our regular framework upgrade cadence; not blocking since we don't accept user-controlled email via the affected rule."
},
{
"advisoryId": "PKSA-x678-4z45-v3d5",
"packageName": "phpoffice/phpspreadsheet",
"severity": "critical",
"cve": "CVE-2026-45034",
"title": "PhpSpreadsheet has a patch bypass for CVE-2026-34084",
"owner": "ops",
"target_date": "2026-07-15",
"notes": "We don't load spreadsheet files from user input; the SSRF/RCE path is gated. Upgrade in next phpoffice/phpspreadsheet bump."
},
{
"advisoryId": "PKSA-gz3f-3cz3-3wsw",
"packageName": "phpoffice/phpspreadsheet",
"severity": "high",
"cve": "CVE-2026-40902",
"title": "CPU DoS via unbounded row number in XLSX Row Dimensions",
"owner": "ops",
"target_date": "2026-07-15",
"notes": "Same upgrade as the critical bypass above; the DoS path is also gated since user-supplied XLSX is not accepted."
},
{
"advisoryId": "PKSA-x13r-n4wc-4gcr",
"packageName": "phpoffice/phpspreadsheet",
"severity": "high",
"cve": "CVE-2026-40863",
"title": "CPU DoS via unbounded row index in SpreadsheetML XML Reader",
"owner": "ops",
"target_date": "2026-07-15",
"notes": "Bundled with the other phpoffice/phpspreadsheet upgrades."
},
{
"advisoryId": "PKSA-8cfg-tzhf-fr83",
"packageName": "phpoffice/phpspreadsheet",
"severity": "critical",
"cve": "CVE-2026-34084",
"title": "SSRF/RCE in IOFactory::load when $filename is user controlled",
"owner": "ops",
"target_date": "2026-07-15",
"notes": "User-supplied filename never reaches IOFactory::load; all reports run on internally-generated paths. Bundled upgrade."
},
{
"advisoryId": "PKSA-smrh-yx37-92ws",
"packageName": "phpseclib/phpseclib",
"severity": "high",
"cve": "CVE-2026-44167",
"title": "OID amplification DoS in ASN1::decodeOID() (CVE-2024-27355 mitigation bypass)",
"owner": "ops",
"target_date": "2026-08-01",
"notes": "Transitive via aws SDK paths; clears when phpseclib upgrades to the patched release."
},
{
"advisoryId": "PKSA-km2b-zc3b-mjm3",
"packageName": "phpseclib/phpseclib",
"severity": "high",
"cve": "CVE-2026-32935",
"title": "AES-CBC unpadding padding-oracle timing attack",
"owner": "ops",
"target_date": "2026-08-01",
"notes": "Same package upgrade as the OID DoS finding."
},
{
"advisoryId": "PKSA-2n2k-66v2-bwg3",
"packageName": "symfony/mime",
"severity": "high",
"cve": "CVE-2026-45067",
"title": "Email Header / SMTP Command Injection via CRLF in Address",
"owner": "ops",
"target_date": "2026-07-15",
"notes": "Customer email addresses are validated via Form Request rules before reaching the Address class; injection vector is gated. Clears on next symfony/mime upgrade (waits for Laravel framework bump)."
}
]
}