SOAP HTTP 客户端在限制响应缓冲区增长时,使用了一项依赖于有符号整数溢出的检查机制。由于有符号整数溢出属于未定义行为,因此该检查并不保证一定会触发。当此检查被编译器优化掉时,恶意的 SOAP 服务器可以诱导客户端分配一个远小于后续写入数据量的缓冲区,从而导致堆缓冲区溢出。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91765 | 7.5 HIGH | SOAP: Unbounded Recursion in Server-Side cleanup_xml_node |
| CVE-2026-17545 | 6.9 MEDIUM | PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can ca |
| CVE-2026-91767 | 6.5 MEDIUM | Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard |
| CVE-2026-91768 | 6.5 MEDIUM | IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcm |
| CVE-2026-92842 | 5.9 MEDIUM | OOB read / info leak in convert.* stream filters when line-break-chars contains NUL |
| CVE-2026-91766 | 5.9 MEDIUM | Cross-origin credential leak in HTTP stream wrapper redirects |
| CVE-2026-93682 | 5.8 MEDIUM | Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Loca |
| CVE-2026-6103 | 4.3 MEDIUM | Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection |
| CVE-2026-91769 | 4.3 MEDIUM | TLS Hostname Verification Falls Back to CN After SAN Mismatch |
| CVE-2025-1218 | 3.4 LOW | Various packet overreads in mysqlnd_writeprotocol.c |
No comments yet