THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x7rj-f32v-7jjg (high) — Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS

[GHSA] GHSA-x7rj-f32v-7jjg (high) — Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS

medgithub_advisoriesPublished 2026-08-28

GHSA-x7rj-f32v-7jjg Severity: high CVE: CVE-2026-57584

Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS

## Summary

Every Phalcon MVC application built with a default router (`new Phalcon\Mvc\Router()` or `new Phalcon\Mvc\Router(true)`, which is the normal case) registers a built-in route whose compiled PCRE pattern is `#^/([\w0-9\

Indicators of compromise

Original source: https://github.com/advisories/GHSA-x7rj-f32v-7jjg