🛡️ CVE-2020-7071 — libphp
Description
FILTER_VALIDATE_URL accepts URLs with invalid userinfo
In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to functions that rely on URL being valid to mis-parse the URL and produce wrong data as components of the URL.
Affected software
CVE-2020-7071 is recorded against 3 packages.
- libphp
- php
- php-min
Timeline and source
Published on 11 August 2025. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
bugs.php.net (Web)
lists.debian.org (Web)
nvd.nist.gov (Web)
security.gentoo.org (Web)
security.netapp.com (Web)
www.debian.org (Web)
www.oracle.com (Web)
www.tenable.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| libphp | — | — |
| php | — | — |
| php-min | — | — |
References
Similar Threats
- Critical CVE-2020-7059
- Critical CVE-2020-7060
- Critical CVE-2020-7061
- High CVE-2020-7062
- Medium CVE-2020-7063
Vulnerability Monitoring
Track new vulnerabilities in libphp
CVE-2020-7071 is rated CVSS 5.0 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.
Set Up Free Alerts →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.