CyberICT

CVE-2023-28115

Microsoft · Published August 7, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Snappy vulnerable to PHAR deserialization, allowing remote code execution. Snappy vulnerable to PHAR deserialization, allowing remote code execution

Affected Products

  • azl3 snappy 1.1.10-2 on Azure Linux 3.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H