Skip to content

Bump PHPUnit to ^9.6.33 to fix CVE-2026-24765 (Dependabot alert #3) - #21

Merged
basi merged 8 commits into
mainfrom
work/dependabot-3-phpunit-cve-2026-24765
Aug 27, 2026
Merged

basi merged 8 commits into
mainfrom
work/dependabot-3-phpunit-cve-2026-24765

Conversation

@basi

@basi basi commented Aug 26, 2026 •

Copy link
Copy Markdown
Owner

Summary

Resolves Dependabot alert #3: https://github.com/basi/cakephp2-php8/security/dependabot/3

  • CVE-2026-24765 / GHSA-vvj3-c3rp-c85p (severity: high, CVSS 7.8, CWE-502): PHPUnit's PHPT code-coverage handling (cleanupForCoverage()) deserializes .coverage files via unserialize without an allowed_classes restriction. Patched in 9.6.33 (latest 9.6.x is 9.6.36).

This repository contains no *.phpt tests and CI collects no coverage, so there is no actual attack surface here — the manifest changes below are what resolve the alert. The PR additionally un-breaks CI (every composer install had been failing since Nov 2025) and restores real TLS peer-verification test coverage. Updated after a code review (3 findings addressed — see "Review response" below), then brought up to date with main (#23 switched the CI matrix from PHP 8.2 to 8.4), which required one PHP 8.4 test-expectation fix.

Changes

  1. app/composer.json: remove phpunit/phpunit from require-dev (previously 3.7.*, the constraint the alert fired on)
    • The app skeleton pins upstream cakephp/cakephp ~2.9 and php >= 5.3.0; any modern PHPUnit constraint there would be self-contradictory (upstream 2.x CakeTestCase extends the PHPUnit 3 era PHPUnit_Framework_TestCase, and PHPUnit 9.6 requires PHP >= 7.3). The skeleton is not exercised by CI nor by the documented consumption path (README instructs the VCS-repository method), so the dev dependency is vestigial. Removing it resolves the alert without advertising an impossible install
  2. composer.json: phpunit/phpunit ^9.5 → ^9.6.33 — raises the floor to the first patched version (a fresh install resolves to 9.6.36)
  3. composer.json: ID-scoped advisory policy to un-break CI. Since Composer 2.9, resolution of advisory-affected packages is blocked by default, and cakephp/cakephp-codesniffer ^1.0.0 → squizlabs/php_codesniffer ^1.4 made every CI composer install fail since Nov 2025 (build(deps): bump actions/checkout from 5 to 6 #19, build(deps): bump actions/cache from 4 to 5 #20). config.policy.advisories.ignore-id now lists exactly the two blocking advisories — PKSA-6vdd-n4sx-knhy (phpcs 1.x arbitrary shell execution, GHSA-mhfv-8rc9-w38c) and CVE-2026-67434 (phpcs OS command injection, PKSA-rdkp-vv9z-mjkg / GHSA-hmqg-cxww-wqhq) — each with "on-audit": false and a reason, so only install/update blocking is lifted while composer audit and the post-install warning keep reporting both advisories
    • Note on on-audit semantics: Composer's 06-config.md prose currently describes on-block/on-audit inverted relative to the implementation. The actual behavior (per AdvisoriesPolicyConfig::getIgnoreIdForOperation() in 2.10.2 and verified empirically) is that the flags scope where the ignore applies: "on-audit": false = ignored for blocking, still reported by audit
  4. lib/Cake/Test/Case/Network/Http/HttpSocketTest.php + new lib/Cake/Test/test_app/tls_server.php: testVerifyPeer now verifies TLS peer rejection against a local TLS server with a runtime-generated self-signed certificate instead of a dead external host
    • The previous target tv.eurosport.com no longer resolves, which had left the test permanently skipped (no regression coverage for peer verification). Nothing is committed to the repository and nothing can expire: the helper generates a throwaway certificate at runtime — CN=127.0.0.1 with subjectAltName = IP:127.0.0.1, serverAuth EKU and CA:FALSE, built from an explicit OpenSSL config so the fixture does not depend on a system openssl.cnf
    • The test owns the temporary files (OpenSSL config + PEM) and passes their paths to the child over argv (array-form proc_open, no shell escaping); startup is handed back as a JSON line, and the child's stderr is folded into the failure message. Fixture startup problems are test failures, not skips, so environment rot stays visible
    • The assertion is two-sided: a positive control with ssl_allow_self_signed => true must receive an HTTP 200 from the fixture first (proving the server and certificate genuinely work for 127.0.0.1), then the default-configuration client must be rejected with Failed to enable crypto. The child serves both connections with real HTTP responses, and its exit code 0 and the removal of both temporary files are asserted as well
  5. lib/Cake/Test/Case/Utility/DebuggerTest.php: update the expected highlight_string() pattern for PHP 8.4 (the <code> element may carry attributes and colors are emitted as 6-digit hex). Needed because the CI matrix now includes PHP 8.4 (see Run CI tests on PHP 8.4 instead of 8.2 #23)

Verification

  • Manifest validity: composer validate passes for both root and app/ (Composer 2.10.2)
  • Clean resolution without a lock file (replicating CI): phpunit/phpunit → 9.6.36, squizlabs/php_codesniffer → 1.5.6, zero problems, exit 0
  • Advisory visibility preserved: post-install prints Found 2 security vulnerability advisories affecting 1 package. and composer audit lists both advisories in full — only the install-time block is lifted
  • CI on the current head (with main merged in, matrix PHP 8.0 × mysql/pgsql/sqlite + PHP 8.4 × mysql): all 4 jobs pass — run 32952486089. The hardened testVerifyPeer runs its assertions (not skipped) on every job
  • The initial, pre-hardening fixture was also verified locally on PHP 8.0.30/8.2.33 (Docker, sqlite) before the follow-up strengthened it

Review response

Finding Resolution
[High] app/composer.json deps incompatible with PHPUnit 9 and unverified by CI Removed the vestigial phpunit/phpunit dev dependency from the skeleton (option 1 of the review); the skeleton reverts to a coherent legacy snapshot
[High] Package-wide advisory ignore hides current and future phpcs advisories Replaced with ignore-id entries for exactly the two blocking advisories, scoped to lift blocking only; composer audit keeps reporting them. Backporting a phpcs fix / migrating the ruleset remains a separate task
[Medium] testVerifyPeer permanently skipped Replaced the dead external host with a local self-signed TLS fixture; a follow-up hardened it (SAN certificate from an explicit OpenSSL config, positive control via ssl_allow_self_signed, child stderr/exit-code propagation, fixture problems fail instead of skip)

Out of scope (known separate issues)

🤖 Generated with Claude Code

basi and others added 2 commits August 26, 2026 16:17
- app/composer.json pinned phpunit 3.7.* which cannot resolve to any
  patched release, triggering Dependabot alert #3 (GHSA-vvj3-c3rp-c85p,
  unsafe deserialization in PHPT code coverage handling). Raise it and
  the root constraint to ^9.6.33 so only patched 9.6.x can resolve;
  a fresh install currently resolves to 9.6.36.
- Ignore the squizlabs/php_codesniffer 1.x security advisories via
  config.policy.advisories.ignore: Composer >= 2.9 refuses to install
  advisory-affected packages, which has broken every CI composer
  install since Nov 2025. The 1.x line is required by the CakePHP2
  coding standard (cakephp-codesniffer 1.x), is dev-only, and is
  frozen upstream.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
HttpSocketTest::testVerifyPeer connects to https://tv.eurosport.com/
expecting a TLS peer-verification failure, but that hostname no longer
resolves, so the SocketException carries a DNS error instead of
'Failed to enable crypto' and the assertion fails on every CI job.
Skip on name-resolution failure, in the same style as the existing
environmental skip conditions in this test. This was masked until now
because CI had been failing at composer install since Nov 2025.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@basi basi changed the title PHPUnit を 9.6.33 以上に更新して CVE-2026-24765 (Dependabot alert #3) を解消 Bump PHPUnit to ^9.6.33 to fix CVE-2026-24765 (Dependabot alert #3) Aug 26, 2026
basi and others added 4 commits August 26, 2026 17:18
The skeleton pins upstream cakephp/cakephp ~2.9 and php >= 5.3.0, which
are incompatible with PHPUnit 9 (upstream CakeTestCase extends the
PHPUnit 3 era PHPUnit_Framework_TestCase, and PHPUnit 9.6 requires
PHP >= 7.3). The skeleton is not exercised by CI nor by the documented
consumption path (the README instructs the VCS-repository method), so
the dev dependency is vestigial. Removing it resolves Dependabot
alert #3 for this manifest without advertising an impossible install.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Replace the package-wide policy.advisories.ignore for
squizlabs/php_codesniffer with ignore-id entries for the two advisories
that block resolution (PKSA-6vdd-n4sx-knhy and CVE-2026-67434), scoped
with on-audit: false so only install/update blocking is lifted while
composer audit keeps reporting them. Verified against Composer 2.10.2:
resolution succeeds (php_codesniffer 1.5.6) and both advisories remain
visible in composer audit and in the post-install warning. The scoping
semantics follow the implementation (AdvisoriesPolicyConfig) and the
doc example; the prose in Composer's 06-config.md currently describes
on-block/on-audit inverted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
testVerifyPeer previously depended on an external bad-certificate host
(tv.eurosport.com) whose DNS no longer resolves, leaving the test
permanently skipped and TLS peer verification without regression
coverage. Replace it with a helper (lib/Cake/Test/test_app/tls_server.php)
that generates a throwaway self-signed certificate at runtime and serves
one TLS connection on 127.0.0.1, so the verification failure is asserted
deterministically with no network dependency. An unexpectedly successful
request is now a test failure instead of a skip.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@basi basi self-assigned this Aug 26, 2026
@basi
basi marked this pull request as ready for review August 26, 2026 09:26

@shin2ro shin2ro left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@basi
basi merged commit 961238c into main Aug 27, 2026
4 checks passed
@basi
basi deleted the work/dependabot-3-phpunit-cve-2026-24765 branch August 27, 2026 19:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants