league/flysystem
Packagist2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting league/flysystempage 1 of 1
- CVE-2021-32708CRITICALCVSS 9.8EG 9.8fixed in 1.1.4 or 2.1.1, by version range2021-06-24
vulnerable: 2.0.0 ... 2.1.0 (10 versions)
Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code rem…
- CVE-2026-102601LOWCVSS 3.5EG 3.5fixed in 3.35.32026-09-29
vulnerable: 0.1.0 ... 3.9.0 (256 versions)
Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both fal…
Check whether league/flysystem is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for league/flysystem CVEs against the assets you own.
Book a Demo →