{"id":"DEBIAN-CVE-2026-41570","details":"PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=value command-line arguments without neutralizing INI metacharacters. Because PHP's INI parser interprets \" as a string delimiter, ; as the start of a comment, and most importantly a newline as a directive separator, a value containing a newline is parsed by the child process as multiple INI directives. An attacker able to influence a single INI value can therefore inject arbitrary additional directives into the child's configuration, including auto_prepend_file, extension, disable_functions, open_basedir, and others. Setting auto_prepend_file to an attacker-controlled path yields remote code execution in the child process. This issue has been patched in versions 12.5.22 and 13.1.6.","modified":"2026-06-01T14:01:36.846513047Z","published":"2026-05-08T15:16:40.420Z","withdrawn":"2026-06-01T14:01:36.846512907Z","upstream":["CVE-2026-41570"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-41570"}],"affected":[{"package":{"name":"phpunit","ecosystem":"Debian:11","purl":"pkg:deb/debian/phpunit?arch=source&distro=bullseye"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["10.0.11-1","10.0.12-1","10.0.13-1","10.0.14-1","10.0.15-1","10.0.16-1","10.0.18-1","10.0.19-1","10.0.7-1","10.0.9-1","10.1.2-1","10.1.3-1","10.2.0-1","10.2.1-1","10.2.2-1","10.2.3-1","10.2.4-1","10.2.5-1","10.2.6-1","10.3.1-1","10.3.2-1","10.3.3-1","10.3.4-1","10.3.5-1","10.4.0-1","10.4.1-1","10.4.2-1","10.5.1-1","10.5.2-1","10.5.3-1","10.5.5-1","10.5.6-1","10.5.7-1","10.5.8-1","10.5.9-1","11.0.1-1","11.0.2-1","11.0.3-1","11.0.4-1","11.0.5-1","11.0.6-1","11.0.8-1","11.0.9-1","11.1.1-1","11.1.2-1","11.1.3-1","11.2.2-1","11.2.5-1","11.2.6-1","11.2.7-1","11.2.8-1","11.3.0-1","11.3.1-1","11.3.3-1","11.3.4-1","11.3.5-1","11.3.6-1","11.4.1-1","11.4.2-1","11.4.3-1","11.4.4-1","11.5.10-1","11.5.12-1","11.5.12-2","11.5.13-1","11.5.14-1","11.5.15-1","11.5.17-1","11.5.18-1","11.5.19-1","11.5.2-1","11.5.2-2","11.5.2-3","11.5.2-4","11.5.3-1","11.5.5-1","11.5.6-1","11.5.7-1","11.5.8-1","11.5.9-1","12.0.10-1","12.0.2-1","12.0.3-1","12.0.4-1","12.0.5-1","12.0.7-1","12.0.7-2","12.0.8-1","12.0.9-1","12.1.0-1","12.1.2-1","12.1.3-1","12.1.4-1","12.1.5-1","12.1.6-1","12.2.1-1","12.2.2-1","12.2.3-1","12.2.5-1","12.2.6-1","12.2.7-1","12.3.0-1","12.3.11-1","12.3.12-1","12.3.14-1","12.3.15-1","12.3.15-2","12.3.3-1","12.3.4-1","12.3.5-1","12.3.6-1","12.3.7-1","12.3.8-1","12.4.0-1","12.4.1-1","12.4.2-1","12.4.3-1","12.4.4-1","12.4.5-1","12.5.1-1","12.5.2-1","12.5.3-1","12.5.4-1","12.5.5-1","12.5.6-1","12.5.7-1","12.5.8-1","12.5.9-1","13.0.0-1","13.0.0-2","13.0.1-1","13.0.2-1","13.0.3-1","13.0.5-1","13.0.6-1","13.0.6-2","13.0.6-3","13.1.0-1","13.1.1-1","13.1.3-1","13.1.5-1","13.1.6-1","13.1.7-1","13.1.8+ds-1","13.1.9+ds-1","9.5.10-1","9.5.11-1","9.5.12-1","9.5.13-1","9.5.14-1","9.5.16-1","9.5.2-1","9.5.2-1+deb11u1","9.5.20-1","9.5.20-2","9.5.20-3","9.5.21-1","9.5.23-1","9.5.24-1","9.5.24-2","9.5.24-3","9.5.25-1","9.5.26-1","9.5.27-1","9.5.28-1","9.5.3-1","9.5.4-1","9.5.5-1","9.5.6-1","9.5.7-1","9.6.0-1","9.6.1-1","9.6.10-1","9.6.11-1","9.6.12-1","9.6.13-1","9.6.15-1","9.6.16-1","9.6.17-1","9.6.18-1","9.6.19-1","9.6.20-1","9.6.21-1","9.6.22-1","9.6.3-1","9.6.4-1","9.6.5-1","9.6.6-1","9.6.7-1","9.6.9-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41570.json"}},{"package":{"name":"phpunit","ecosystem":"Debian:12","purl":"pkg:deb/debian/phpunit?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["10.0.11-1","10.0.12-1","10.0.13-1","10.0.14-1","10.0.15-1","10.0.16-1","10.0.18-1","10.0.19-1","10.0.7-1","10.0.9-1","10.1.2-1","10.1.3-1","10.2.0-1","10.2.1-1","10.2.2-1","10.2.3-1","10.2.4-1","10.2.5-1","10.2.6-1","10.3.1-1","10.3.2-1","10.3.3-1","10.3.4-1","10.3.5-1","10.4.0-1","10.4.1-1","10.4.2-1","10.5.1-1","10.5.2-1","10.5.3-1","10.5.5-1","10.5.6-1","10.5.7-1","10.5.8-1","10.5.9-1","11.0.1-1","11.0.2-1","11.0.3-1","11.0.4-1","11.0.5-1","11.0.6-1","11.0.8-1","11.0.9-1","11.1.1-1","11.1.2-1","11.1.3-1","11.2.2-1","11.2.5-1","11.2.6-1","11.2.7-1","11.2.8-1","11.3.0-1","11.3.1-1","11.3.3-1","11.3.4-1","11.3.5-1","11.3.6-1","11.4.1-1","11.4.2-1","11.4.3-1","11.4.4-1","11.5.10-1","11.5.12-1","11.5.12-2","11.5.13-1","11.5.14-1","11.5.15-1","11.5.17-1","11.5.18-1","11.5.19-1","11.5.2-1","11.5.2-2","11.5.2-3","11.5.2-4","11.5.3-1","11.5.5-1","11.5.6-1","11.5.7-1","11.5.8-1","11.5.9-1","12.0.10-1","12.0.2-1","12.0.3-1","12.0.4-1","12.0.5-1","12.0.7-1","12.0.7-2","12.0.8-1","12.0.9-1","12.1.0-1","12.1.2-1","12.1.3-1","12.1.4-1","12.1.5-1","12.1.6-1","12.2.1-1","12.2.2-1","12.2.3-1","12.2.5-1","12.2.6-1","12.2.7-1","12.3.0-1","12.3.11-1","12.3.12-1","12.3.14-1","12.3.15-1","12.3.15-2","12.3.3-1","12.3.4-1","12.3.5-1","12.3.6-1","12.3.7-1","12.3.8-1","12.4.0-1","12.4.1-1","12.4.2-1","12.4.3-1","12.4.4-1","12.4.5-1","12.5.1-1","12.5.2-1","12.5.3-1","12.5.4-1","12.5.5-1","12.5.6-1","12.5.7-1","12.5.8-1","12.5.9-1","13.0.0-1","13.0.0-2","13.0.1-1","13.0.2-1","13.0.3-1","13.0.5-1","13.0.6-1","13.0.6-2","13.0.6-3","13.1.0-1","13.1.1-1","13.1.3-1","13.1.5-1","13.1.6-1","13.1.7-1","13.1.8+ds-1","13.1.9+ds-1","9.6.10-1","9.6.11-1","9.6.12-1","9.6.13-1","9.6.15-1","9.6.16-1","9.6.17-1","9.6.18-1","9.6.19-1","9.6.20-1","9.6.21-1","9.6.22-1","9.6.7-1","9.6.7-1+deb12u1","9.6.9-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41570.json"}},{"package":{"name":"phpunit","ecosystem":"Debian:13","purl":"pkg:deb/debian/phpunit?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["11.5.19-1","11.5.19-1+deb13u1","12.0.10-1","12.0.2-1","12.0.3-1","12.0.4-1","12.0.5-1","12.0.7-1","12.0.7-2","12.0.8-1","12.0.9-1","12.1.0-1","12.1.2-1","12.1.3-1","12.1.4-1","12.1.5-1","12.1.6-1","12.2.1-1","12.2.2-1","12.2.3-1","12.2.5-1","12.2.6-1","12.2.7-1","12.3.0-1","12.3.11-1","12.3.12-1","12.3.14-1","12.3.15-1","12.3.15-2","12.3.3-1","12.3.4-1","12.3.5-1","12.3.6-1","12.3.7-1","12.3.8-1","12.4.0-1","12.4.1-1","12.4.2-1","12.4.3-1","12.4.4-1","12.4.5-1","12.5.1-1","12.5.2-1","12.5.3-1","12.5.4-1","12.5.5-1","12.5.6-1","12.5.7-1","12.5.8-1","12.5.9-1","13.0.0-1","13.0.0-2","13.0.1-1","13.0.2-1","13.0.3-1","13.0.5-1","13.0.6-1","13.0.6-2","13.0.6-3","13.1.0-1","13.1.1-1","13.1.3-1","13.1.5-1","13.1.6-1","13.1.7-1","13.1.8+ds-1","13.1.9+ds-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41570.json"}},{"package":{"name":"phpunit","ecosystem":"Debian:14","purl":"pkg:deb/debian/phpunit?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["11.5.19-1","12.0.10-1","12.0.2-1","12.0.3-1","12.0.4-1","12.0.5-1","12.0.7-1","12.0.7-2","12.0.8-1","12.0.9-1","12.1.0-1","12.1.2-1","12.1.3-1","12.1.4-1","12.1.5-1","12.1.6-1","12.2.1-1","12.2.2-1","12.2.3-1","12.2.5-1","12.2.6-1","12.2.7-1","12.3.0-1","12.3.11-1","12.3.12-1","12.3.14-1","12.3.15-1","12.3.15-2","12.3.3-1","12.3.4-1","12.3.5-1","12.3.6-1","12.3.7-1","12.3.8-1","12.4.0-1","12.4.1-1","12.4.2-1","12.4.3-1","12.4.4-1","12.4.5-1","12.5.1-1","12.5.2-1","12.5.3-1","12.5.4-1","12.5.5-1","12.5.6-1","12.5.7-1","12.5.8-1","12.5.9-1","13.0.0-1","13.0.0-2","13.0.1-1","13.0.2-1","13.0.3-1","13.0.5-1","13.0.6-1","13.0.6-2","13.0.6-3","13.1.0-1","13.1.1-1","13.1.3-1","13.1.5-1","13.1.6-1","13.1.7-1","13.1.8+ds-1","13.1.9+ds-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41570.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}