CVE-2011-5021: Phpids

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

PHPIDS before 0.7 does not properly implement Regular Expression Denial of Service (ReDoS) filters, which allows remote attackers to bypass rulesets and add PHP sequences to a file via unspecified vectors.

Affected products

  • Phpids Phpids: up to and including 0.6.5; version 0.6.4 only

Published 2011-12-29. Last modified 2026-06-16.