CVE-2026-25235

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers to guess verification tokens and potentially verify election account requests without authorization. This issue has been patched in version 1.33.0.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Feb 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 19:16

Updated : 2026-02-03 19:16


NVD link : CVE-2026-25235

Mitre link : CVE-2026-25235

CVE.ORG link : CVE-2026-25235


JSON object : View

Products Affected

No product.

CWE
CWE-337

Predictable Seed in Pseudo-Random Number Generator (PRNG)