216.73.217.22

CVE-2026-7262

· Published 10/05/2026 05:16 · Modified 10/05/2026 05:16

Labels: CVE-2026-7262 2026-05-10CVE-2026-7262CWE-476[email protected]

Essential information

Published
10/05/2026 05:16
Modified
10/05/2026 05:16
Author
Creator
CVSS
2.9 LOW (v3) 2.9 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
php / php cpe:2.3:a:php:php:8.2.*:<8.2.31>*:*:*:*:*:*:*
php / php cpe:2.3:a:php:php:8.3.*:<8.3.31>*:*:*:*:*:*:*
php / php cpe:2.3:a:php:php:8.4.*:<8.4.21>*:*:*:*:*:*:*
php / php cpe:2.3:a:php:php:8.5.*:<8.5.6>*:*:*:*:*:*:*

References