CVE-2026-53933
Deferred Deferred - Pending Action

Maravel Framework Side-Channel Route Parameter Disclosure

Vulnerability report for CVE-2026-53933, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: GitHub, Inc.

Description

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.73.1 has a side-channel information disclosure issue. When a route was compiled with dynamic placeholders (e.g., `/api/v1/users/{id}`), the raw string placeholder key was mistakenly registered into the flat static route checklist. An attacker scanning endpoints could intentionally pass the literal template syntax (e.g., `GET /api/v1/users/{id}`) to force an unexpected match against the static map. Because the dynamic tree engine was bypassed, no arguments were captured. This forced modern PHP 8+ versions to throw a native `ArgumentCountError`, resulting in a 500 Internal Server Error instead of a uniform 404 Not Found. By tracking which fuzz patterns exploded into a 500 error, a malicious actor could programmatically profile and map out internal route parameter names and controller schemas. Version 10.73.1 contains a patch. As a workaround, mitigate this side-channel leak by implementing a defensive check in a global middleware. This will reject any literal brace patterns before they reach the router engine.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
maravel maravel to 10.73.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-203 The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Maravel, a PHP framework using dependency injection, had a side-channel information disclosure issue in versions before 10.73.1. When routes with dynamic placeholders like /api/v1/users/{id} were compiled, the raw placeholder string was incorrectly added to the static route checklist. Attackers could exploit this by sending requests with literal template syntax like GET /api/v1/users/{id}, causing a 500 error instead of 404. This allowed them to map internal routes and parameters by tracking which requests triggered errors.

Detection Guidance

To detect this vulnerability, monitor for HTTP 500 errors when sending requests with literal template syntax like GET /api/v1/users/{id}. Use tools like curl or Burp Suite to send such requests and check for 500 responses instead of 404. Example: curl -X GET http://target.com/api/v1/users/{id}

Impact Analysis

An attacker could profile your application's internal routes and controller schemas by observing which requests cause 500 errors. This exposes sensitive information about your application structure, potentially aiding further attacks. The vulnerability does not directly expose data but provides reconnaissance capabilities to malicious actors.

Mitigation Strategies

Upgrade to Maravel version 10.73.1 or later. As a temporary workaround, implement a global middleware to reject requests containing literal brace patterns before they reach the router engine.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53933. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart