Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-91767— Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN

Quick assessment

Affected
PHP Group PHP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 中的 函数存在下溢漏洞。当 TLS 服务器证书包含的通配符名称其字面字符部分的总长度大于正在验证的主机名时,该函数会向 传递一个负数的长度参数。攻击者可通过提供包含此类证书的恶意服务器,导致 PHP 客户端从堆分配区域的末尾向后读取多达 字节的数据。由于默认客户端流的 选项默认启用,因此该漏洞路径在任何默认配置下均可被触发。

CVSS 6.5 · Medium EPSS 0.15% · P4

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91767

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN
Source: CVE Program / CVE List V5
Vulnerability Description
php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
PHP Group PHP 8.2.* ~ 8.2.34 -

II. Public POCs for CVE-2026-91767

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91767

请登录查看更多情报信息。

Other References for CVE-2026-91767 (1)

Same Patch Batch · PHP Group · 2026-09-25 · 11 CVEs total

CVE-2026-91765 7.5 HIGH SOAP: Unbounded Recursion in Server-Side cleanup_xml_node
CVE-2026-17545 6.9 MEDIUM PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can ca
CVE-2026-91768 6.5 MEDIUM IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcm
CVE-2025-14181 6.5 MEDIUM Integer overflow to buffer overflow in soap HTTP parsing
CVE-2026-92842 5.9 MEDIUM OOB read / info leak in convert.* stream filters when line-break-chars contains NUL
CVE-2026-91766 5.9 MEDIUM Cross-origin credential leak in HTTP stream wrapper redirects
CVE-2026-93682 5.8 MEDIUM Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Loca
CVE-2026-6103 4.3 MEDIUM Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection
CVE-2026-91769 4.3 MEDIUM TLS Hostname Verification Falls Back to CN After SAN Mismatch
CVE-2025-1218 3.4 LOW Various packet overreads in mysqlnd_writeprotocol.c

IV. Related Vulnerabilities

V. Comments for CVE-2026-91767

No comments yet


Leave a comment