PHP是PHP开源的一种在服务器端执行的脚本语言。 PHP 8.2.31之前版本、8.3.31之前版本、8.4.21之前版本和8.5.6之前版本存在代码问题漏洞,该漏洞源于当SOAP服务器配置了类型映射时,解码过程中在缺少值元素的情况下检查了错误的变量,导致空指针取消引用造成段错误,远程未认证攻击者可利用此漏洞使PHP SOAP服务器进程崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6722 | 9.5 CRITICAL | Use-After-Free in SOAP using Apache map |
| CVE-2026-7258 | Out-of-bounds read in urldecode() on NetBSD | |
| CVE-2026-7261 | SoapServer session-persisted object use-after-free via SOAP header fault | |
| CVE-2026-7259 | Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() | |
| CVE-2026-7568 | Signed integer overflow in metaphone() | |
| CVE-2026-6735 | XSS within PHP-FPM status endpoint | |
| CVE-2025-14179 | SQL injection in pdo_firebird via NUL bytes in quoted strings | |
| CVE-2026-7263 | DoS attack via DOMNode::C14N() | |
| CVE-2026-6104 | Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding |
No comments yet