DFIR Lab[verified]@DFIR_LabPatch
The tweet announces CVE‑2026‑41570, highlights its high‑severity RCE risk via INI injection, and urges immediate patching to specific newer versions.
Kaitan ID Security[verified]@KaitanSecurityDisclosure
The post announces a high‑severity CVE (CVE‑2026‑41570) affecting PHPUnit 12.5.21 and 13.1.5, where PHP INI settings are forwarded to child processes, with a CVSS score of 7.8 and a link to a full analysis.
Gray Hats@the_yellow_fallPatch
The tweet announces that PHPUnit CVE‑2026‑41570 enables remote code execution via newline injection in CI/CD pipelines and urges users to update to versions 12.5.22 or 13.1.6 to patch the issue.
Kai Wei@KaiWei_capperDisclosure
A new PHPUnit vulnerability (CVE‑2026‑41570) was disclosed during an upgrade, with links to the official advisory and a security article, but no exploit details, patch information, or active exploitation claim were provided.
CVE@CVEnewDisclosure
The post discloses that PHPUnit in specific versions propagates PHP INI settings to child processes, potentially compromising test isolation.