Skip to content

Harden cache deserialization calls - #90

Merged
Alkarex merged 1 commit into
FreshRSS:freshrssfrom
Inverle:harden-cache-deserialization
Sep 8, 2026
Merged

Alkarex merged 1 commit into
FreshRSS:freshrssfrom
Inverle:harden-cache-deserialization

Conversation

@Inverle

@Inverle Inverle commented Sep 8, 2026

Copy link
Copy Markdown
Member

@Inverle

Inverle commented Sep 8, 2026 •

Copy link
Copy Markdown
Member Author

I assume we aren't using any other cache implementations than File (MySQL, Redis, Memcached, etc.)?

@Alkarex
Alkarex merged commit ec17fd8 into FreshRSS:freshrss Sep 8, 2026
11 checks passed
@Inverle
Inverle deleted the harden-cache-deserialization branch September 8, 2026 21:31
@Alkarex

Alkarex commented Sep 8, 2026

Copy link
Copy Markdown
Member

It could be worth submitting upstream

Alkarex added a commit to FreshRSS/FreshRSS that referenced this pull request Sep 8, 2026
* SimplePie: Harden cache deserialization calls

To reduce impact if a maliciously provided cache file is somehow loaded, e.g. from a manipulated backup or some kind of external arbitrary file write vulnerability.

* Sync our SimplePie

FreshRSS/simplepie#90

---------

Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants