Back to browse
GitHub Repository

PHP 8 Sandbox Escape

87 starsPHP

PHP 8 disable_functions bypass PoC

by m0x41nos·Mar 3, 2026·29 points·10 comments

AI Analysis

●●SolidWizardryBig Brain

Deterministic PHP 8 disable_functions bypass via DateInterval heap corruption.

Strengths
  • Demonstrates novel use-after-free exploitation path in widely-deployed PHP versions
  • Tested across CLI, PHP-FPM, Apache module with reproducible results
  • Clear mitigation advice: sandboxing alone cannot secure memory-unsafe PHP
Weaknesses
  • Limited scope: only affects PHP 8.2–8.5 on Unix; no Windows support documented
  • No practical mitigation beyond upgrading PHP or fundamental architecture changes
Category
Target Audience

PHP security researchers, penetration testers, system administrators

Similar To

CVE-2024-27956 · PHP security advisories

Similar Projects

OtherMid

No JavaScript Club

Forces you to disable JavaScript to enter a directory of JavaScript-free websites.

CozyNiche Gem
basilikum
1031mo ago