Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-31629

51
FAUCET Score

CVE-2022-31629 is a medium-severity vulnerability affecting PHP versions prior to 7.4.31, 8.0.24, and 8.1.11, allowing network and same-site attackers to bypass cookie security mechanisms. Specifically, it enables an attacker to set an insecure cookie that PHP applications incorrectly interpret as a secure __Host- or __Secure- cookie. The attack requires user interaction (UI:R) and has a high impact on integrity (I:H), with a CVSS score of 6.5. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.4.31CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 8.0.0, < 8.0.24CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 8.1.0, < 8.1.11CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
49.34%
Probability of exploitation in next 30 days
EPSS Percentile
98.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.4934 is in the 99th percentile among its peer group of 26,221 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: 19641-16823
microsoftpatch availablevia msrc
Product: cbl2 php on CBL Mariner 2.0
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: php:7.4-8080020230118140634.cc342424
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: php:8.1-9020020230120141750.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: php-0:8.0.27-1.el9_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: php:8.0-8070020230118114629.ef331662
View patch
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-php73-php

Vendor Advisories (2)

redhatCVE-2022-31629Moderate

php: standard insecure cookie could be treated as a '__Host-' or '__Secure-' cookie by PHP applications

Sep 29, 2022
microsoft2022-Sep/CVE-2022-31629Moderate

$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities

Sep 13, 2022

References

lists.fedoraproject.org / archives/list/[email protected]/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY
lists.fedoraproject.org / archives/list/[email protected]/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY
bugs.php.net / bug.php
ExploitPermissions RequiredVendor Advisory
lists.debian.org / debian-lts-announce/2022/12/msg00030.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/2L5SUVYGAKSWODUQPZFBUB3AL6E6CSEV
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/LSJVPJTX7T3J5V7XHR4MFNHZGP44R5XE
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY
security.gentoo.org / glsa/202211-03
Third Party Advisory
security.netapp.com / advisory/ntap-20221209-0001
Third Party Advisory
debian.org / security/2022/dsa-5277
Third Party Advisory
openwall.com / lists/oss-security/2024/04/12/11