CVE-2022-31629 - CVE House
Back to Database
Status published Unknown CVE-2022-31629

$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities

Vulnerability Description

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-31629

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • reported by squarcina at gmail dot com

Affected Vendor

Affected Software

PHP
Vulnerable Versions:
7.4.X, 8.0.X, 8.1.X

Timeline

Official Publish: September 28th, 2022
Last Modified: November 4th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)