[php-src] Issue #11295: preg_match with \m modifier has unexpected behavior
| From: | Geompse | Date: | Mon, 22 May 2023 13:45:49 +0000 |
| Subject: | [php-src] Issue #11295: preg_match with \m modifier has unexpected behavior | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-244503@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/11295
Author: Geompse
### Description
The following code:
```php
<?php
var_dump(preg_match('#^a$#m','a'."\n".'b'));
```
Resulted in this output:
```
int(1)
```
But I expected this output instead:
```
false
```
There is no technical bug as the implementation is valid, but there is a fonctional bug as the
developer is mislead. This can lead to security breaches because you might believe that some user
input would be sanitize while it is not. Example :
```php
<?php
$_REQUEST['username'] = '%%%'."\n".'lol';
if(!preg_match('#^[a-z]+$#m',(string)($_REQUEST['username']??null)))
die();
echo 'did not die';
```
**I think it would be nice to throw a E_DEPRECATED when \m is used with preg_match**
Note : the \m modifier is working as expected with preg_match_all
### PHP Version
PHP 8.1.17
### Operating System
_No response_