CVE-2026-7262
Published: May 10, 2026
Modified: May 11, 2026
Description
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element. This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.
| Vendor | Product | Versions |
|---|---|---|
PHP Group | PHP | affected 8.2.* - < 8.2.31affected 8.3.* - < 8.3.31affected 8.4.* - < 8.4.21affected 8.5.* - < 8.5.6 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now