CPU Exhaustion Vulnerability in Phalcon MVC Framework
CVE-2026-57584

8.7HIGH

Key Information:

Vendor

Phalcon

Status
Vendor
CVE Published:
10 July 2026

What is CVE-2026-57584?

In the Phalcon MVC framework, prior to version 5.15.0, a flaw exists that can lead to CPU exhaustion due to catastrophic backtracking in regular expression processing. The built-in routing system, when configured with nested quantifiers, processes attacker-controlled URIs, potentially allowing crafted paths with repeated slashes or encoded newlines to exploit this vulnerability. This can result in excessive resource consumption, impacting application performance and stability. Users are urged to upgrade to version 5.15.0 or later to mitigate this issue.

Affected Version(s)

cphalcon < 5.15.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.