CVE-2023-0567
📛 CVE Title
password_verify() always returns true for some invalid hashes
Description
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- php
- CVSS severity
- HIGH
- CVSS score
- 7.7 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N- Effective score
- 7.7 / 10 HIGH source: CNA overview
- MSRC score
- 7.7 / 10 HIGH MS rating: Important
- CWE(s)
-
CWE-916 - Reserved
- 2023-01-29
- Published
- 2023-02-16 07:15 UTC
- Last updated
- 2024-08-02 07:17 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/0xxx/CVE-2023-0567.json
- Linked Threat
- CVE-2023-0567 — password_verify() always returns true for some invalid hashes
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-12609 - Assigner
- php
- Published
- Feb 16, 2023, 6:15:50 AM
- Updated
- Aug 2, 2024, 5:17:50 AM
- EUVD base score (CVSS 3.1)
-
7.7 / 10
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - EUVD-reported EPSS
- 0.1400
- Vendors
- PHP Group
- Products
-
PHP (8.0.x <8.0.28)PHP (8.2.x <8.2.3)PHP (8.1.x <8.1.16)
ENISA description: In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid.
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-11 02:00 UTC (source: CVRF).
- MS severity
- Important
- MS CVSS base score
- 7.7 / 10 (temporal 7.7)
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - Release
- 2026-Aug
Microsoft remediations / KB articles (2)
- CBL-Mariner Releases — Vendor Fix / Security Update (fixed build 8.1.16-1)
- https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade — None Available / CBL-Mariner Releases
Microsoft FAQ (1)
Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| PHP Group | PHP |
8.0.x (affected),
8.1.x (affected),
8.2.x (affected)
|
— |
Vendor references (2)
References embedded in the original CVE record by the assigning CNA.
Web references (17)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- None Available msrc
- MSRC update guide: CVE-2023-0567 msrc
- https://bugs.php.net/bug.php?id=81744 rapid7:bugs.php.net
- https://errata.rockylinux.org/RLSA-2024:10952 rapid7:errata.rockylinux.org
- https://errata.rockylinux.org/RLSA-2024:0387 rapid7:errata.rockylinux.org
- https://errata.rockylinux.org/RLSA-2023:5926 rapid7:errata.rockylinux.org
- https://errata.rockylinux.org/RLSA-2023:5927 rapid7:errata.rockylinux.org
- https://errata.almalinux.org/9/ALSA-2023-5926.html rapid7:errata.almalinux.org
- https://errata.almalinux.org/8/ALSA-2023-5927.html rapid7:errata.almalinux.org
- https://errata.almalinux.org/8/ALSA-2024-10952.html rapid7:errata.almalinux.org
- https://errata.almalinux.org/9/ALSA-2024-0387.html rapid7:errata.almalinux.org
- https://security.alpinelinux.org/vuln/CVE-2023-0567 rapid7:security.alpinelinux.org
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12609 rapid7:euvd.enisa.europa.eu
- https://www.cve.org/CVERecord?id=CVE-2023-0567 rapid7:www.cve.org
- https://alas.aws.amazon.com/AL2023/ALAS-2023-139.html rapid7:alas.aws.amazon.com
- https://attackerkb.com/topics/CVE-2023-0567 rapid7:attackerkb.com
- http://cwe.mitre.org/data/definitions/916.html rapid7:cwe.mitre.org
Remediations (16)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:cybersecuritynews.com
Microsoft has rolled out a new cumulative update, KB5089573, for Windows 11 versions 25H2 and 24H2, targeting a critical installation failure that affected users following the May 2026 Patch Tuesday release.
2026-06-02 01:49 UTC -
web:nvd.nist.gov
The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...
2026-06-02 01:49 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-06-02 01:49 UTC -
web:www.pcworld.com
Microsoft has begun rolling out update KB5072753, a new emergency out-of-band patch for Windows 11 that fixes a bug that was introduced in November's KB5068966 update.
2026-06-02 01:49 UTC -
web:www.rapid7.com
Microsoft is publishing 66 new vulnerabilities today, which is far fewer than we've come to expect in recent months. However, the lone zero-day vulnerability this month demands attention.
2026-06-02 01:49 UTC -
web:www.zdnet.com
Install Microsoft's emergency Windows patch now - what it fixes and why it was rushed out Microsoft issued an out-of-band fix after its latest update introduced a nasty surprise.
2026-06-02 01:49 UTC -
web:www.bleepingcomputer.com
Microsoft has released out-of-band (OOB) security updates to patch a critical-severity Windows Server Update Service (WSUS) vulnerability with publicly available proof-of-concept exploit code.
2026-05-22 05:35 UTC -
web:www.cisa.gov
Updated October 29, 2025: CISA has updated this Alert to include revised information on vulnerable product identification, potential threat activity detections, and additional resources. Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025), CVE -2025-59287
2026-05-22 05:35 UTC -
web:www.cisco.com
This document describes a list of software versions that have incorporated fixes for Cisco IOS® XE Software Web UI Cisco bug ID CSCwh87343.
2026-05-22 05:35 UTC -
web:www.pcworld.com
This month's Patch Tuesday includes an actively exploited Office zero-day vulnerability and several critical RCE bugs in Windows and Remote Desktop.
2026-05-22 05:35 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-05-22 05:35 UTC -
web:cybersecuritynews.com
Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2.
2026-05-22 05:35 UTC -
web:www.virustotal.com
VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.
2026-05-22 05:35 UTC -
web:nvd.nist.gov
Information Technology Laboratory National Vulnerability Database Vulnerabilities
2026-05-22 05:35 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 05:35 UTC -
web:translate.google.com
Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.
2026-05-22 05:35 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-0567.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:17:50.104Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://security.netapp.com/advisory/ntap-20230331-0008/"
},
{
"tags": [
"x_transferred"
],
"url": "https://bugs.php.net/bug.php?id=81744"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:a:php_group:php:8.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:php_group:php:8.1.0:*:*:*:*:*:*:*",
"cpe:2.3:a:php_group:php:8.2.0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "php",
"vendor": "php_group",
"versions": [
{
"lessThan": "80.28",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"lessThan": "8.1.16",
"status": "affected",
"version": "8.1.0",
"versionType": "semver"
},
{
"lessThan": "8.2.3",
"status": "affected",
"version": "8.2.0",
"versionType": "semver"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2023-0567",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-08-01T15:34:47.733360Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-916",
"description": "CWE-916 Use of Password Hash With Insufficient Computational Effort",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-08-01T15:34:50.014Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "PHP",
"programRoutines": [
{
"name": "password_verify"
}
],
"repo": "https://github.com/php/php-src",
"vendor": "PHP Group",
"versions": [
{
"lessThan": "8.0.28",
"status": "affected",
"version": "8.0.x",
"versionType": "semver"
},
{
"lessThan": "8.1.16",
"status": "affected",
"version": "8.1.x",
"versionType": "semver"
},
{
"lessThan": "8.2.3",
"status": "affected",
"version": "8.2.x",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "remediation developer",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Tim D\u00fcsterhus"
},
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "tech at mkdgs dot fr"
}
],
"datePublic": "2023-02-13T05:40:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<br><p>In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid. </p>"
}
],
"value": "In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "NONE",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-03-01T05:45:13.020Z",
"orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
"shortName": "php"
},
"references": [
{
"url": "https://bugs.php.net/bug.php?id=81744"
},
{
"url": "https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "password_verify() always returns true for some invalid hashes",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
"assignerShortName": "php",
"cveId": "CVE-2023-0567",
"datePublished": "2023-02-16T06:15:50.127Z",
"dateReserved": "2023-01-29T07:45:55.380Z",
"dateUpdated": "2024-08-02T05:17:50.104Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}