Skip to content

Bump phpunit/phpunit to fix CVE-2026-24765#255

Merged
janedbal merged 1 commit intomasterfrom
fix/phpunit-cve-2026-24765
Jan 28, 2026
Merged

Bump phpunit/phpunit to fix CVE-2026-24765#255
janedbal merged 1 commit intomasterfrom
fix/phpunit-cve-2026-24765

Conversation

@janedbal
Copy link
Member

Summary

  • Bumps phpunit/phpunit from ^10.5.58 to ^10.5.62 to fix CVE-2026-24765 (unsafe deserialization in PHPT code coverage handling, CVSS 7.8 High)

Unsafe deserialization vulnerability in PHPT code coverage handling.
GHSA-vvj3-c3rp-c85p
@janedbal janedbal merged commit b159fac into master Jan 28, 2026
80 of 96 checks passed
@janedbal janedbal deleted the fix/phpunit-cve-2026-24765 branch January 28, 2026 10:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant