Unserialize security policy

From: Date: Wed, 02 Aug 2017 20:02:39 +0000
Subject: Unserialize security policy
Groups: php.internals 
Request: Send a blank email to internals+get-100147@lists.php.net to get a copy of this message
Hi, https://bugs.php.net/bug.php?id=75006 has been marked as a non-security bug, with the justification that unserialize() should not be fed untrusted input. While we do document that unserialize() shouldn't be used on untrusted input, we have always treated these as security bugs in the past. Could somebody please clarify our current security policy with regard to unserialize? Thanks, Nikita

« previous php.internals (#100147) next »