Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-7258

Опубликовано: 10 мая 2026
Источник: debian
EPSS Низкий

Описание

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.4fixed8.4.21-1package
php8.2removedpackage
php7.4removedpackage

Примечания

  • https://github.com/php/php-src/security/advisories/GHSA-m8rr-4c36-8gq4

  • https://github.com/php/php-src/commit/b8dad9314c1e225a1a2d50608e4e7d478c34365c

  • https://github.com/php/php-src/commit/dc9e21b81c143faa9677bb0cf157e83960a24d0d

  • https://github.com/php/php-src/commit/398b7dabfbd2e8f4f4ed2065dbcf3e3794e8ca47

  • https://github.com/php/php-src/commit/a38418777f65780d9d622197677e90567690fc07

EPSS

Процентиль: 26%
0.00337
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.

CVSS3: 5.9
redhat
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.

CVSS3: 7.5
nvd
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.

msrc
3 месяца назад

Out-of-bounds read in urldecode() on NetBSD

github
3 месяца назад

Out-of-bounds read in urldecode()

EPSS

Процентиль: 26%
0.00337
Низкий