Post cover image
Photo by Dmytro Bukhantsov on Unsplash

June 22, 2026

The PHP Deserialization Bug Class That Keeps Coming Back

One unserialize() call. One attacker cookie. One file written to disk. The PHP bug class that won’t die, with verified working code.

By Ann R.

19 min read