Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-7260

Опубликовано: 30 июл. 2026
Источник: debian
EPSS Низкий

Описание

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.4fixed8.4.24-1package
php8.2removedpackage
php7.4removedpackage

Примечания

  • https://github.com/php/php-src/security/advisories/GHSA-vc5h-9ppw-p5f3

  • Fixed by: https://github.com/php/php-src/commit/16af1694dd4e0d0e4a24f90740651d3053edffa3 (php-8.4.24)

EPSS

Процентиль: 6%
0.00168
Низкий

Связанные уязвимости

ubuntu
4 дня назад

(Circular symbolic links in phar archives could lead to unbounded recur ...)

nvd
4 дня назад

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 5.5
github
4 дня назад

Stack overflow in phar with circular symlinks

EPSS

Процентиль: 6%
0.00168
Низкий