Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q4f2-39gr-45jh | Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint |
Fri, 20 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adminer
Adminer adminer |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:adminer:adminer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Adminer
Adminer adminer |
Tue, 10 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vrana
Vrana adminer |
|
| Vendors & Products |
Vrana
Vrana adminer |
Mon, 09 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and accepts POST data from any source. An attacker can POST version[] parameter which PHP converts to an array. On next page load, openssl_verify() receives this array instead of string and throws TypeError, returning HTTP 500 to all users. Upgrade to Adminer 5.4.2. | |
| Title | Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-10T15:57:46.865Z
Reserved: 2026-02-06T21:08:39.130Z
Link: CVE-2026-25892
Updated: 2026-02-10T15:39:31.665Z
Status : Analyzed
Published: 2026-02-09T22:16:04.023
Modified: 2026-02-20T20:24:32.147
Link: CVE-2026-25892
No data.
OpenCVE Enrichment
Updated: 2026-04-18T13:00:08Z
Github GHSA