Index
Search
Search the public record. Drafts and scheduled notes are not included.
Critical
news
Smarty cache injection is CVE-2026-82531
GHSA-3w63-v7pm-cq9x / CVE-2026-82531: Smarty before 4.5.8 and 5.x before 5.8.5 can write forged SmartyNocache content from assigned data into regenerated PHP caches during extends inheritance, enabling RCE on include. CVSS 4.0 9.2. Public PoC exists. Fixed in 4.5.8 and 5.8.5. Not in CISA KEV.
Published 2h ago
CriticalPoC Available
CVE-2026-82531
Smarty template cache code injection via extends inheritance
RCE
Published 29h ago