在 中的 函数存在下溢漏洞。当 TLS 服务器证书包含的通配符名称其字面字符部分的总长度大于正在验证的主机名时,该函数会向 传递一个负数的长度参数。攻击者可通过提供包含此类证书的恶意服务器,导致 PHP 客户端从堆分配区域的末尾向后读取多达 字节的数据。由于默认客户端流的 选项默认启用,因此该漏洞路径在任何默认配置下均可被触发。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91765 | 7.5 HIGH | SOAP: Unbounded Recursion in Server-Side cleanup_xml_node |
| CVE-2026-17545 | 6.9 MEDIUM | PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can ca |
| CVE-2026-91768 | 6.5 MEDIUM | IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcm |
| CVE-2025-14181 | 6.5 MEDIUM | Integer overflow to buffer overflow in soap HTTP parsing |
| CVE-2026-92842 | 5.9 MEDIUM | OOB read / info leak in convert.* stream filters when line-break-chars contains NUL |
| CVE-2026-91766 | 5.9 MEDIUM | Cross-origin credential leak in HTTP stream wrapper redirects |
| CVE-2026-93682 | 5.8 MEDIUM | Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Loca |
| CVE-2026-6103 | 4.3 MEDIUM | Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection |
| CVE-2026-91769 | 4.3 MEDIUM | TLS Hostname Verification Falls Back to CN After SAN Mismatch |
| CVE-2025-1218 | 3.4 LOW | Various packet overreads in mysqlnd_writeprotocol.c |
No comments yet