CVE-2026-102601
Published 29 September 2026 · tracked since 30 September 2026
Description
Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes P
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-72897 HIGH 7.5
- CVE-2026-54873
- CVE-2026-54875 LOW 3.7
- CVE-2026-19743 HIGH 7.8
- CVE-2026-35189
- CVE-2026-35191
- CVE-2026-42772
- CVE-2026-102598
- CVE-2026-102600 HIGH 7.5
- CVE-2026-102630 MEDIUM 4.7