CVE-2024-3096

PHP function password_verify can erroneously return true when argument contains NUL

In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.


We have discovered 89,456 live websites that are affected by CVE-2024-3096.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains89,456 live websites (1.29% of PHP install base)
Vulnerable Versions
  • from 8.1 through 8.1
  • from 8.2 through 8.2
  • from 8.3 through 8.3
Vulnerable Versions Count3 versions ( 0.57% of all versions)


Common Weakness Enumeration

CWE-20 Improper Input Validation



Details

  • Published - Apr 29, 2024
  • Updated - Nov 4, 2025

Credits

  • Eric Stern (reporter)

Website Distribution by Country

Number of websites using CVE-2024-3096
United States2,162 websites



France73,481 websites
Brazil3,714 websites
Poland2,763 websites
Spain1,414 websites
Belgium1,251 websites
Italy1,223 websites
Germany667 websites
Russia373 websites
GB231 websites

Website Distribution by TLD

Number of websites using CVE-2024-3096
.com31,835 websites
.fr31,189 websites
.org3,758 websites
.be3,425 websites
.com.br3,098 websites
.pl2,765 websites
.net2,283 websites
.it1,662 websites
.eu1,293 websites
.es1,167 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-3096

Top websites that are affected by CVE-2024-3096. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.fr France**,***
*************.com United States**,***
**************.net France**,***
*************.com France**,***
*******.com United States**,***
******.de Germany**,***
***.de France**,***
******.co France**,***
**********************.org France**,***
******************.fr France**,***
See full domain list

FAQ

CVE-2024-3096 is Improper Input Validation in PHP
A total of 89,456 websites have been identified as vulnerable to CVE-2024-3096, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2024-3096 vulnerability.
PHP versions up to and including 8.3 are vulnerable to CVE-2024-3096.