CPU Exhaustion Vulnerability in Phalcon MVC Framework
CVE-2026-57584
8.7HIGH
What is CVE-2026-57584?
In the Phalcon MVC framework, prior to version 5.15.0, a flaw exists that can lead to CPU exhaustion due to catastrophic backtracking in regular expression processing. The built-in routing system, when configured with nested quantifiers, processes attacker-controlled URIs, potentially allowing crafted paths with repeated slashes or encoded newlines to exploit this vulnerability. This can result in excessive resource consumption, impacting application performance and stability. Users are urged to upgrade to version 5.15.0 or later to mitigate this issue.
Affected Version(s)
cphalcon < 5.15.0
