laravel/reverb
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications.
Activity
- Latest release
- 1mo ago
- Total releases
- 44
- Cadence
- ~12 days
- Last 12 months
- 13
Reach
- Stars
- 1.6k
Details
- License
- MIT
- First release
- Mar 12, 2024
| Version | Released | |
|---|---|---|
v1.11.1
patch
|
v1.11.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v1.11.0
minor
|
v1.11.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v1.10.2
patch
| ||
v1.10.1
patch
| ||
v1.10.0
minor
| ||
v1.9.0
minor
| ||
v1.8.1
patch
| ||
v1.8.0
minor
| ||
v1.7.1
patch
| ||
v1.7.0
minor
|
v1.7.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v1.6.3
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.6.2
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.6.1
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.6.0
minor
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.5.1
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.5.0
minor
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.4.8
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.4.8
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v1.4.7
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.4.6
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.4.5
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.4.5
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v1.4.4
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.4.3
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.4.2
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.4.1
patch
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.4.0
minor
1 CVE
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.3.1
patch
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
v1.3.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v1.3.0
minor
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
v1.3.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v1.2.0
minor
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.1.0
minor
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0
initial
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0-beta14
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0-beta13
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0-beta12
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
v1.0.0-beta12
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v1.0.0-beta11
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
v1.0.0-beta11
pre
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v1.0.0-beta10
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0-beta9
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0-beta8
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0-beta7
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0-beta6
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0-beta5
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0-beta4
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
v1.0.0-beta4
pre
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
v1.0.0-beta3
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0-beta2
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev | ||
v1.0.0-beta1
pre
2 CVEs
CVE-2026-23524
GHSA-m27r-m6rx-mhm4
Jan 21, 2026
Laravel Redis Horizontal Scaling Insecure Deserialization
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThis vulnerability affects Laravel Reverb versions prior to v1.7.0 when horizontal scaling is enabled ( The exploitability of this vulnerability is increased because Redis servers are commonly deployed without authentication. With horizontal scaling enabled, Reverb servers communicate via Redis PubSub. Reverb previously passed data from the Redis channel directly into PHP’s Risk: Remote Code Execution (RCE) PatchesThis vulnerability is fixed in Laravel Reverb v1.7.0. Update your dependency to WorkaroundsIf you cannot upgrade to v1.7.0, you should apply the following mitigations:
CreditsThis vulnerability was discovered and responsibly reported by Mohammad Yaser Abo-Elmaaty @m0h4mmad Affected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 22 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-50347
GHSA-pfrr-xvrf-pxjx
Oct 31, 2024
Laravel Reverb Missing API Signature Verification
High
Network
Low
None
None
ImpactA community member disclosed an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message from a backend service or for obtaining statistical information (such as number of connections) about a given channel. The verification signature is a hash comprised of different parts of the request signed by the app's secret key. The signature is sent as part of the request and should be regenerated by Reverb. Only when both the signature in the request and the one generated by Reverb match should the request be allowed. This helps to verify the request came from a known source.
The following endpoints were affected:
PatchesThe issue was resolved by #252 and the patch released in v1.4.0. ReferencesAffected versions
v1.0.0
v1.0.0-beta1
v1.0.0-beta10
v1.0.0-beta11
v1.0.0-beta12
v1.0.0-beta13
v1.0.0-beta14
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-beta4
v1.0.0-beta5
v1.0.0-beta6
+ 7 more Show less
v1.0.0-beta7
v1.0.0-beta8
v1.0.0-beta9
v1.1.0
v1.2.0
v1.3.0
v1.3.1
Fixed in
1.4.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
v1.0.0-beta1
pre
Dependencies (13)
+ 5 more
Changelog
|