Description
Maravel, a PHP framework oriented towards dependency injection, prior to version 10.73.1 has a side-channel information disclosure issue. When a route was compiled with dynamic placeholders (e.g., `/api/v1/users/{id}`), the raw string placeholder key was mistakenly registered into the flat static route checklist. An attacker scanning endpoints could intentionally pass the literal template syntax (e.g., `GET /api/v1/users/{id}`) to force an unexpected match against the static map. Because the dynamic tree engine was bypassed, no arguments were captured. This forced modern PHP 8+ versions to throw a native `ArgumentCountError`, resulting in a 500 Internal Server Error instead of a uniform 404 Not Found. By tracking which fuzz patterns exploded into a 500 error, a malicious actor could programmatically profile and map out internal route parameter names and controller schemas. Version 10.73.1 contains a patch. As a workaround, mitigate this side-channel leak by implementing a defensive check in a global middleware. This will reject any literal brace patterns before they reach the router engine.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Side-Channel Information Disclosure via Error Oracle
Action: Immediate Patch
AI Analysis

Impact

Maravel, a PHP framework oriented toward dependency injection, contains a flaw in its route handling logic. When a dynamic route template such as "/api/v1/users/{id}" is compiled, the raw placeholder name is incorrectly added to a flat static route list. If an attacker supplies a request that includes the literal brace syntax, the request bypasses the dynamic route engine and causes PHP 8+ to throw an ArgumentCountError, resulting in a 500 Internal Server Error instead of the expected 404. The varying error responses provide an error‑oracle side‑channel that allows the attacker to determine which route patterns trigger the error, revealing internal parameter names, controller mappings, and application structure (CWE‑203).

Affected Systems

The vulnerability is present in Maravel framework versions prior to 10.73.1. Users deploying these versions on PHP 8 or newer are at risk. Version 10.73.1 and later contain the vendor patch, and the package is distributed under macropay-solutions/maravel-framework.

Risk and Exploitability

With a CVSS score of 6.9 the issue is considered moderate severity. No EPSS value is available, and the vulnerability is not listed in CISA KEV, indicating that widespread exploitation has not been reported. The attack requires only automated HTTP fuzzing of exposed endpoints and does not need privileged access. An adversary can use the response type difference to map application routes, which may assist in locating sensitive endpoints for subsequent attacks.

Generated by OpenCVE AI on September 9, 2026 at 09:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Maravel version 10.73.1 or later to apply the vendor patch that corrects the route compilation bug.
  • Implement a global middleware that inspects incoming request URLs and rejects any literal brace patterns (e.g., "{" or "}") before they reach the router, preventing the error‑oracle behavior as a temporary workaround.
  • Configure a web application firewall or reverse‑proxy rule to detect and block requests containing literal brace characters, reducing the ability of attackers to trigger the error response.

Generated by OpenCVE AI on September 9, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Macropay-solutions
Macropay-solutions maravel-framework
Vendors & Products Macropay-solutions
Macropay-solutions maravel-framework

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description Maravel, a PHP framework oriented towards dependency injection, prior to version 10.73.1 has a side-channel information disclosure issue. When a route was compiled with dynamic placeholders (e.g., `/api/v1/users/{id}`), the raw string placeholder key was mistakenly registered into the flat static route checklist. An attacker scanning endpoints could intentionally pass the literal template syntax (e.g., `GET /api/v1/users/{id}`) to force an unexpected match against the static map. Because the dynamic tree engine was bypassed, no arguments were captured. This forced modern PHP 8+ versions to throw a native `ArgumentCountError`, resulting in a 500 Internal Server Error instead of a uniform 404 Not Found. By tracking which fuzz patterns exploded into a 500 error, a malicious actor could programmatically profile and map out internal route parameter names and controller schemas. Version 10.73.1 contains a patch. As a workaround, mitigate this side-channel leak by implementing a defensive check in a global middleware. This will reject any literal brace patterns before they reach the router engine.
Title Maravel-Framework Vulnerable to Side-Channel Information Disclosure (Error Oracle) via Dynamic Route Fuzzing
Weaknesses CWE-203
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Macropay-solutions Maravel-framework
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T13:15:37.549Z

Reserved: 2026-06-11T15:46:12.317Z

Link: CVE-2026-53933

cve-icon Vulnrichment

Updated: 2026-09-09T13:14:59.548Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T22:18:14.743

Modified: 2026-09-10T19:58:20.507

Link: CVE-2026-53933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:03:04Z

Weaknesses