Lune

ICSE2026Top-tier venue

CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web Applications

Yichao Xu, Mingqing Kang, Neil Thimmaiah, Rigel Gjomemo, V. N. Venkatakrishnan, Yinzhi Cao

2026Year

Abstract

PHP, a widely-used programming language in Web development, contains powerful dynamic features (e.g., dynamic function name construction), making static detection of taint-style vulnerabilities like SQL injection and XSS challenging. State-of-the-art (SoTA) static approaches perform call graph-guided backward dataflow tracking, thus failing to analyze those dynamic PHP features, like variable functions, and control structures, which results in high false positives and negatives. In this paper, we design and implement CoBrA, a context-, branch-sensitive approach to detect taint-style vulnerabilities in PHP-based Web applications. The key innovations are the abstract domain graph (ADG), which is used to efficiently guide the analysis, and a ‘‘stretch-relax’’ algorithm, which enables accurate resolution of PHP dynamic features and efficient inter-procedural taint propagation. Our evaluation of CoBrA’s prototype identified 54 zero-day vulnerabilities in 19 real-world applications with nine CVE identifiers assigned, achieved 88.66% detection rate with under 0.3% false positives on a PHP tarpits dataset, and outperformed four SoTA tools across all test datasets with reasonable time and space consumption.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

Builds on9

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines