CVE-2026-62996

NameCVE-2026-62996
DescriptionSmarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped resource name to be used to read the contents of arbitrary local files accessible to the PHP process. An attacker able to author or influence a template's resource reference could exploit this to disclose sensitive file contents outside the intended template/config scope. This issue is fixed in version 5.8.4.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
smarty3 (PTS)bookworm, bookworm (security)3.1.47-2+deb12u1fixed
forky, sid, trixie3.1.48-2fixed
smarty4 (PTS)bookworm, bookworm (security)4.3.0-1+deb12u2fixed
forky, sid, trixie4.5.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
smarty3source(unstable)(not affected)
smarty4source(unstable)(not affected)

Notes

- smarty4 <not-affected> (Vulnerable code not present)
- smarty3 <not-affected> (Vulnerable code not present)
https://github.com/smarty-php/smarty/security/advisories/GHSA-rjhh-76wf-8xmw
https://github.com/smarty-php/smarty/pull/1195
Fixed by: https://github.com/smarty-php/smarty/commit/3c9f77a2e06ce319ae0092496af32cc8f3adc52e (v5.8.4)

Search for package or bug name: Reporting problems