CVE-2023-28115
Microsoft · Published August 7, 2026
9.8
CVSS v3.1
CRITICALPatch availableGet patch
Description
Snappy vulnerable to PHAR deserialization, allowing remote code execution. Snappy vulnerable to PHAR deserialization, allowing remote code execution
Affected Products
- azl3 snappy 1.1.10-2 on Azure Linux 3.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H