CVE Explorer
CVE-2026-22034
Snuffleupagus is a module that raises the cost of attacks against website by killing bug classes and providing a virtual patching system. On deployments of Snuffleupagus prior to version 0.13.0 with the non-default upload validation feature enabled and configured to use one of the upstream validation scripts based on Vulcan Logic Disassembler (VLD) while the VLD extension is not available to the CLI SAPI, all files from multipart POST requests are evaluated as PHP code. The issue was fixed in ve
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"snuffleupagus","vendor":"jvoisin","versions":[{"status":"affected","version":"< 0.13.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:78b620987d381b074ea926bd6dd5167b794783a82d2994d7781fdf72ce69c3f6 · sha256:d13b8ba1c34b9a59… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":9.2,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:78b620987d381b074ea926bd6dd5167b794783a82d2994d7781fdf72ce69c3f6 · sha256:d13b8ba1c34b9a59… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-636","description":"CWE-636: Not Failing Securely ('Failing Open')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:78b620987d381b074ea926bd6dd5167b794783a82d2994d7781fdf72ce69c3f6 · sha256:d13b8ba1c34b9a59… · /containers/cna/problemTypes/0/descriptions/0
Source references
8 source assertions{"name":"https://github.com/jvoisin/snuffleupagus/blob/9278dc77bab2a219e770a1b31dd6797bc9070e37/src/sp_upload_validation.c#L92-L100","tags":["x_refsource_MISC"],"url":"https://github.com/jvoisin/snuffleupagus/blob/9278dc77bab2a219e770a1b31dd6797bc9070e37/src/sp_upload_validation.c#L92-L100"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78b620987d381b074ea926bd6dd5167b794783a82d2994d7781fdf72ce69c3f6 · sha256:d13b8ba1c34b9a59… · /containers/cna/references/2
{"name":"https://github.com/jvoisin/snuffleupagus/blob/v0.12.0/scripts/upload_validation.php","tags":["x_refsource_MISC"],"url":"https://github.com/jvoisin/snuffleupagus/blob/v0.12.0/scripts/upload_validation.php"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78b620987d381b074ea926bd6dd5167b794783a82d2994d7781fdf72ce69c3f6 · sha256:d13b8ba1c34b9a59… · /containers/cna/references/3
{"name":"https://github.com/jvoisin/snuffleupagus/blob/v0.12.0/scripts/upload_validation.py","tags":["x_refsource_MISC"],"url":"https://github.com/jvoisin/snuffleupagus/blob/v0.12.0/scripts/upload_validation.py"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78b620987d381b074ea926bd6dd5167b794783a82d2994d7781fdf72ce69c3f6 · sha256:d13b8ba1c34b9a59… · /containers/cna/references/4
{"name":"https://github.com/jvoisin/snuffleupagus/commit/9278dc77bab2a219e770a1b31dd6797bc9070e37","tags":["x_refsource_MISC"],"url":"https://github.com/jvoisin/snuffleupagus/commit/9278dc77bab2a219e770a1b31dd6797bc9070e37"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78b620987d381b074ea926bd6dd5167b794783a82d2994d7781fdf72ce69c3f6 · sha256:d13b8ba1c34b9a59… · /containers/cna/references/1
{"name":"https://github.com/jvoisin/snuffleupagus/security/advisories/GHSA-c4ch-xw5p-2mvc","tags":["x_refsource_CONFIRM"],"url":"https://github.com/jvoisin/snuffleupagus/security/advisories/GHSA-c4ch-xw5p-2mvc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78b620987d381b074ea926bd6dd5167b794783a82d2994d7781fdf72ce69c3f6 · sha256:d13b8ba1c34b9a59… · /containers/cna/references/0
{"name":"https://github.com/php/php-src/blob/e4098da58a9eaee759d728d98a27d809cde37671/ext/standard/dl.c#L165-L166","tags":["x_refsource_MISC"],"url":"https://github.com/php/php-src/blob/e4098da58a9eaee759d728d98a27d809cde37671/ext/standard/dl.c#L165-L166"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78b620987d381b074ea926bd6dd5167b794783a82d2994d7781fdf72ce69c3f6 · sha256:d13b8ba1c34b9a59… · /containers/cna/references/5
{"name":"https://github.com/php/php-src/blob/e4098da58a9eaee759d728d98a27d809cde37671/main/rfc1867.c#L1269-L1274","tags":["x_refsource_MISC"],"url":"https://github.com/php/php-src/blob/e4098da58a9eaee759d728d98a27d809cde37671/main/rfc1867.c#L1269-L1274"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78b620987d381b074ea926bd6dd5167b794783a82d2994d7781fdf72ce69c3f6 · sha256:d13b8ba1c34b9a59… · /containers/cna/references/6
{"name":"https://snuffleupagus.readthedocs.io/config.html#upload-validation","tags":["x_refsource_MISC"],"url":"https://snuffleupagus.readthedocs.io/config.html#upload-validation"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78b620987d381b074ea926bd6dd5167b794783a82d2994d7781fdf72ce69c3f6 · sha256:d13b8ba1c34b9a59… · /containers/cna/references/7
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.