{"id":"UBUNTU-CVE-2026-41570","details":"PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=value command-line arguments without neutralizing INI metacharacters. Because PHP's INI parser interprets \" as a string delimiter, ; as the start of a comment, and most importantly a newline as a directive separator, a value containing a newline is parsed by the child process as multiple INI directives. An attacker able to influence a single INI value can therefore inject arbitrary additional directives into the child's configuration, including auto_prepend_file, extension, disable_functions, open_basedir, and others. Setting auto_prepend_file to an attacker-controlled path yields remote code execution in the child process. This issue has been patched in versions 12.5.22 and 13.1.6.","modified":"2026-05-20T16:25:41.377471268Z","published":"2026-05-08T15:16:00Z","upstream":["CVE-2026-41570"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-41570"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-41570"},{"type":"REPORT","url":"https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-qrr6-mg7r-m243"},{"type":"REPORT","url":"https://github.com/sebastianbergmann/phpunit/pull/6592"}],"affected":[{"package":{"name":"phpunit","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/phpunit?arch=source&distro=esm-apps%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.7.6-1","4.8.16-1","5.1.3-1ubuntu1","5.1.3-1+build1","5.1.3-1+ubuntu1","5.1.3-1+ubuntu3","5.1.3-1+ubuntu3+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"phpunit","binary_version":"5.1.3-1+ubuntu3+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"}},{"package":{"name":"phpunit","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/phpunit?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.4.6-2","5.4.6-3","6.5.5-1ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"phpunit","binary_version":"6.5.5-1ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"}},{"package":{"name":"phpunit","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/phpunit?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.5.6-1","8.5.2-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"phpunit","binary_version":"8.5.2-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"}},{"package":{"name":"phpunit","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/phpunit?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.5.4-1","9.5.10-1ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"phpunit","binary_version":"9.5.10-1ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"}},{"package":{"name":"phpunit","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/phpunit?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.6.10-1","9.6.13-1","9.6.15-1","9.6.16-1","9.6.17-1"],"ecosystem_specific":{"binaries":[{"binary_version":"9.6.17-1","binary_name":"phpunit"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"}},{"package":{"name":"phpunit","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/phpunit?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["11.5.3-1ubuntu4","11.5.19-1build4"],"ecosystem_specific":{"binaries":[{"binary_name":"phpunit","binary_version":"11.5.19-1build4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"}},{"package":{"name":"phpunit","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/phpunit?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["11.5.19-1build4","13.0.0-2ubuntu6"],"ecosystem_specific":{"binaries":[{"binary_name":"phpunit","binary_version":"13.0.0-2ubuntu6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41570.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}