CVE-2024-2756: PHP Archive Tar

Medium severity, CVSS 6.5. EPSS: 38.1% chance of exploitation in the next 30 days.

Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.

Affected products

  • PHP Archive Tar: any version
  • PHP Group PHP: from 8.1, before 8.1.28 (fixed in 8.1.28); from 8.2, before 8.2.18 (fixed in 8.2.18); from 8.3, before 8.3.5 (fixed in 8.3.5)

Published 2024-04-29. Last modified 2026-06-17.