Pinned
Official bulletin for APSB26-138 detailing impacted versions, severity ratings, CVEs, and fixed releases. Only partial content was accessible during fetch; open the link for full details.
AST-based engine that renders {{...}} templates in a single pass to eliminate re-parsing bugs, with strict, lenient, and compatibility modes. Ships with a drop-in module and CLI to shadow-compare, diff, and safely roll out rendering across emails, CMS, and newsletters.
Standalone PHP script to perform complete encryption key rotation: inventories encrypted values across all tables (including JSON/serialized and nested), re-encrypts them to the latest key, verifies, and safely retires old keys. Includes scan/explain/re-encrypt/verify/retire-keys and code-scan commands with dry-run, dump, and rollback support plus a step-by-step runbook.
Fixes 403s on admin page/block saves by identifying and removing Fastly VCL snippets (accord-rce, accord_rce_1) via the CLI, with steps to clone, validate, and activate a clean version; also covers applying the real CVE-2026-75650 patch or scoping a storefront-only rule.
Covers how the Style Smuggler vulnerability (CVE-2026-75650) works, how to detect potential compromise, and practical remediation and hardening steps. Note: Content could not be fetched; details inferred from the URL.
Offers 41 version-specific patches that backport the official StyleSmuggler (CVE-2026-75650) hotfix to unsupported 2.2.0–2.4.3-p3, with apply steps and guidance on mandatory credential rotation after patching.
Adds interim, application-layer guards against the StyleSmuggler zero-day: validates URL-generator classes, blocks stream-wrapper template paths, sanitizes email template styles, and hardens reports/logs. Includes a block-directive allowlist and optional suppression of failed-payment emails; meant as defense-in-depth until an official fix.
Auto-disables 2FA in developer mode and adds admin/CLI toggles to enable or disable 2FA—and API token generation—in other environments.
Three bash scripts to scan for IoCs and guide cleanup on servers, apply community mitigations via Composer patches and a hardening module, and remotely check GraphQL exposure. Includes DDEV/Warden support, cloud-friendly usage, and step-by-step confirmations.
Patch enforcing CLI-only execution for DI scanners to mitigate StyleSmuggler, adding PHP_SAPI checks in ArrayScanner, ClassesScanner, and XmlInterceptorScanner.
Adds an admin-area file browser and text editor with clickable breadcrumbs, ACL-controlled view/edit access, and a detailed activity log. Enforces strict security with path validation, a sensitive-file denylist, and allowlisted text types only—no upload, delete, or rename actions.