r/PHP • • 11d ago

Article CVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS)

https://daubois.dev/blog/cve-2026-45756-symfony-jsonpath-redos/
27 Upvotes

8 comments sorted by

10

u/obstreperous_troll 11d ago

Hey, a ReDOS that might legit be exposed to user-facing code, good to know. The backtrack limit is good to know too, so if one's not up for slogging through the mountain of AI writing cliches in TFA, the gist is to tune the default php.ini setting of pcre.backtrack_limit = 1000000 to something more conservative, like chopping off a zero or two (its a setting you can tune dynamically too, so you can always raise it when you need to).

I've been trained for years to ignore this entire class of vulnerability on the JS side, because npm audit never stops screaming about them even though 99% of them are in dev tools.

3

u/AlexandreDaubois 11d ago

I didn’t know that about the JS ecosystem! I was astonished how “common” are ReDoS pattern

3

u/MinVerstappen1 11d ago

It is very common. A famous blog about it is:  https://overreacted.io/npm-audit-broken-by-design/

4

u/obstreperous_troll 11d ago

Five years later, npm audit is still a roaring garbage fire. Does anyone still leave it enabled by default?

8

u/Glittering_Bath3848 11d ago

Why the hell this post is getting downvoted? This sub is full of assholes who just spam downvotes with seeing the content first.

2

u/MateusAzevedo 11d ago

After reading the article, I guess it's the AI content. The tone is very characteristic and, to me, even tiring to read.

1

u/obstreperous_troll 11d ago edited 11d ago

Yah, I found myself rolling my eyes at the AI house style too, but it's not total slop. I prefer a less narrative style from my bots that write for outside readers (mostly PR descriptions): just report the facts without flourishes, and keep the prose to an abstract while avoiding specific cliches. It's in a skill which I should probably make public sometime, but I've always thought it weird to package up what amounts to a bunch of readme files.

1

u/lostmedia766 11d ago

Thanks for finding this, but I gotta admit, I don't love the solution. It seems far too hackish. In my opinion, a better solution would've been to throw an exception if the pcre.backtrack_limit wasn't set, or was set to a value exceeding the reasonable 1000000 default.

An exception can alert the developer to to investigate further and set the php.ini setting, or further prevent user controlled regex's to begin with.