CVE-2026-25237

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable PHP code execution if attacker-controlled content reaches the evaluated replacement. This issue has been patched in version 1.33.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pear:pearweb:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:24

Type Values Removed Values Added
Summary
  • (es) PEAR es un framework y sistema de distribución para componentes PHP reutilizables. Antes de la versión 1.33.0, el uso de preg_replace() con el modificador /e en el manejo de correos electrónicos de actualización de errores puede permitir la ejecución de código PHP si contenido controlado por el atacante llega al reemplazo evaluado. Este problema ha sido parcheado en la versión 1.33.0.

05 Feb 2026, 18:05

Type Values Removed Values Added
CPE cpe:2.3:a:pear:pearweb:*:*:*:*:*:*:*:*
References () https://github.com/pear/pearweb/security/advisories/GHSA-vhw6-hqh9-8r23 - () https://github.com/pear/pearweb/security/advisories/GHSA-vhw6-hqh9-8r23 - Vendor Advisory
First Time Pear
Pear pearweb
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

03 Feb 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 19:16

Updated : 2026-06-17 10:24


NVD link : CVE-2026-25237

Mitre link : CVE-2026-25237

CVE.ORG link : CVE-2026-25237


JSON object : View

Products Affected

pear

  • pearweb
CWE
CWE-624

Executable Regular Expression Error