Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘
🐘 Packagist
Not in CISA KEV
HIGH severity

CVE-2021-43822 — jackalope-doctrine-dbal

HIGHFix: jackalope/jackalope-doctrine-dbal@9d179a3

CVE-2021-43822 is a high-severity (CVSS 7.5) SQL Injection vulnerability in jackalope/jackalope-doctrine-dbal. A fix is available for jackalope/jackalope-doctrine-dbal — see the affected versions and patch details below.

SQL injection in jackalope/jackalope-doctrine-dbal

Also known asGHSA-ph98-v78f-jqrm
Published
Updated
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Oct 10, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
1.0%probability of exploitation in next 30 days
Lower Risk+0.03%
Lower risk than most CVEs62th percentile — riskier than 62% of all scored CVEsHighest risk
0.00%0.50%1.00%1.50%0.2%1.0%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2021-43822 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,738 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

1 pkg affected
🐘jackalope/jackalope-doctrine-dbal

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

Impact

Users can provoke SQL injections if they can specify a node name or query.

Patches

Upgrade to version 1.7.4

If that is not possible, you can escape all places where $property is used to filter sv:name in the class Jackalope\Transport\DoctrineDBAL\Query\QOMWalker: XPath::escape($property).

Workarounds

Node names and xpaths can contain " or ; according to the JCR specification. The jackalope component that translates the query object model into doctrine dbal queries does not properly escape the names and paths, so that a accordingly crafted node name can lead to an SQL injection.

If queries are never done from user input, or if you validate the user input to not contain ;, you are not affected.

References

No further references.

For more information

If you have any questions or comments about this advisory:

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistjackalope/jackalope-doctrine-dbalall versions1.7.4composer require jackalope/jackalope-doctrine-dbal:^1.7.4

Affected Products

1 product · 1 configurations
Application
jackalope doctrine-dbaljackalope_doctrine-dbal_project
< 1.7.4
range

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for jackalope/jackalope-doctrine-dbal, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update jackalope/jackalope-doctrine-dbal to 1.7.4 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2021-43822 is resolved across your whole dependency graph.

  3. Workarounds

    Until you can upgrade, make sure every query built from user input uses parameterised statements or a prepared-statement API rather than string concatenation, and reduce the database account's privileges so an injected query cannot read or alter data beyond what the feature needs.

Frequently Asked Questions

### Impact Users can provoke SQL injections if they can specify a node name or query. ### Patches Upgrade to version 1.7.4 If that is not possible, you can escape all places where `$property` is used to filter `sv:name` in the class `Jackalope\Transport\DoctrineDBAL\Query\QOMWalker`: `XPath::escape($property)`. ### Workarounds Node names and xpaths can contain `"` or `;` according to the JCR specification. The jackalope component that translates the query object model into doctrine dbal queries does not properly escape the names and paths, so that a accordingly crafted node name can lead
O3 Security · Impact-Aware SCA

Is CVE-2021-43822 in your dependencies?

Find it across Packagist, including transitive dependencies.

CVE-2021-43822: jackalope-doctrine — Fixed in 1.7.4