CVE-2026-23498
Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not checked being against allow list for the map(...) override. This vulnerability is fixed in 6.7.6.1.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23498.json, https://github.com/shopware/shopware/commit/3966b05590e29432b8485ba47b4fcd14dd0b8475, https://github.com/shopware/shopware/security/advisories/GHSA-7cw6-7h3h-v8pf, https://nvd.nist.gov/vuln/detail/CVE-2026-23498
