saloonphp/saloon
Packagist3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting saloonphp/saloonpage 1 of 1
- CVE-2026-33182HIGHCVSS 7.5EG 7.5✓ Fixed in 4.0.02026-03-26
vulnerable: v0.0.2 ... v3.9.1 (129 versions)
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon combined the connector's base URL with the request endpoint. If the endpoint was a valid absol…
- CVE-2026-33183CRITICALCVSS 9.1EG 9.1✓ Fixed in 4.0.02026-03-26
vulnerable: v0.0.2 ... v3.9.1 (129 versions)
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names were used to build file paths under the configured fixture directory without validation. A name containing path segmen…
- CVE-2026-33942CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.0.02026-03-26
vulnerable: v0.0.2 ... v3.9.1 (129 versions)
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAuthenticator::unserialize() to restore OAuth token state from cache or storage, with allowed…
Check whether saloonphp/saloon is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for saloonphp/saloon CVEs against the assets you own.
Start Free Scan →