Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-7263

Опубликовано: 10 мая 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.4.0 (включая) до 8.4.21 (исключая)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.5.0 (включая) до 8.5.6 (исключая)

EPSS

Процентиль: 28%
0.00353
Низкий

7.5 High

CVSS3

Дефекты

CWE-404
CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

CVSS3: 7.5
redhat
3 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

CVSS3: 7.5
debian
3 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C ...

github
3 месяца назад

DoS attack via DOMNode::C14N()

rocky
около 2 месяцев назад

Important: php8.4 security update

EPSS

Процентиль: 28%
0.00353
Низкий

7.5 High

CVSS3

Дефекты

CWE-404
CWE-835