Skip to content

Regression: SensitiveParameterValue json_encode/var_export leak secret (re-#22487/#3351, Zend/zend_exceptions.c) #23042

Description

@PurHur

Category

Regression · php-src-strict · language · #[\SensitiveParameter] · pillar 4

Problem

debug_backtrace() correctly wraps #[\SensitiveParameter] args in SensitiveParameterValue, and var_dump redacts ((0) { }, no secret). But json_encode() and var_export() on the wrapper still expose the raw secret on the VM. Zend encodes an empty object / empty __set_state array.

Verified 2026-07-25 (host Zend PHP 8.2.32 vs php bin/vm.php):

Repro Zend 8.2+ VM
get_class($sp) SensitiveParameterValue same
json_encode($sp) {} {"value":"secret"}
var_export($sp) __set_state(array( )) 'value' => 'secret'
$sp->getValue() secret (OK) secret (OK)
var_dump contains secret false false

php-src reference

PHP implementation target

  • SensitiveParameterValue implementation in lib/ / ext/standard (or wherever the wrapper class lives) — hide backing value from json_encode / var_export / get_object_vars while keeping getValue() and __debugInfo Zend-shaped
  • PHP-in-PHP; no new runtime/*.c

Repro

./script/docker-exec.sh -- bash -lc 'cat > /tmp/spv_leak.php <<'"'"'PHP'"'"'
<?php
function f(#[\SensitiveParameter] string $password, string $user) {
    return debug_backtrace();
}
$sp = f("secret", "bob")[0]["args"][0];
echo "json=", json_encode($sp), "\n";
echo "var_export=", str_replace("\n", " ", var_export($sp, true)), "\n";
PHP
php bin/vm.php /tmp/spv_leak.php
# expect json={} and empty __set_state — not "secret"'

Done when

  • json_encode($sp) === '{}' (Zend)
  • var_export / __set_state does not include the secret
  • getValue() still returns the real value; var_dump still redacts
  • Compliance .phpt under test/compliance/cases/language/ (or attributes/)
  • php-src-strict; no php-compiler-strict shortcut

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:vmVirtual machinebugSomething isn't workingimplementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claimphase-2:languagePhase 2 – language features

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions