PHP 的 OpenSSL 流对等体验证功能会优先检查证书的 subjectAltName(主题备用名称)条目;若没有任何条目匹配,则回退检查通用名(Common Name, CN)。根据 RFC 6125 的要求,一旦证书提供了任何服务身份标识(如 SAN),就应忽略 CN。然而,当证书中包含一个与请求的对等名称不匹配的 DNS 类型 SAN 条目时,若其 CN 与请求的对等名称相匹配,该证书仍会被接受。因此,客户端信任用于某一名称的证书,可能被攻击者滥用以冒充另一名称。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91765 | 7.5 HIGH | SOAP: Unbounded Recursion in Server-Side cleanup_xml_node |
| CVE-2026-17545 | 6.9 MEDIUM | PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can ca |
| CVE-2026-91767 | 6.5 MEDIUM | Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard |
| CVE-2026-91768 | 6.5 MEDIUM | IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcm |
| CVE-2025-14181 | 6.5 MEDIUM | Integer overflow to buffer overflow in soap HTTP parsing |
| CVE-2026-92842 | 5.9 MEDIUM | OOB read / info leak in convert.* stream filters when line-break-chars contains NUL |
| CVE-2026-91766 | 5.9 MEDIUM | Cross-origin credential leak in HTTP stream wrapper redirects |
| CVE-2026-93682 | 5.8 MEDIUM | Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Loca |
| CVE-2026-6103 | 4.3 MEDIUM | Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection |
| CVE-2025-1218 | 3.4 LOW | Various packet overreads in mysqlnd_writeprotocol.c |
No comments yet