Bug 2512527 (CVE-2026-62996) - CVE-2026-62996 php-smarty: Smarty Security stream restriction bypass through stream: resource
Summary: CVE-2026-62996 php-smarty: Smarty Security stream restriction bypass through ...
Keywords:
Status: NEW
Alias: CVE-2026-62996
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-07 15:21 UTC by OSIDB Bzimport
Modified: 2026-08-07 18:19 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-07 15:21:19 UTC
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped resource name to be used to read the contents of arbitrary local files accessible to the PHP process. An attacker able to author or influence a template's resource reference could exploit this to disclose sensitive file contents outside the intended template/config scope. This issue is fixed in version 5.8.4.


Note You need to log in before you can comment on or make changes to this bug.