Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7262

Опубликовано: 10 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.

A flaw was found in PHP. When a PHP SOAP server has a typemap configured, the apache:Map decoding process checks the incorrect variable in case of a missing value element. This incorrect check leads to a NULL pointer dereference and allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in a denial of service.

Отчет

To exploit this issue, a remote unauthenticated attacker needs to send a malicious request to be processed by the apache:Map decoder, causing a crash in the PHP SOAP server process. Due to this reason, this vulnerability has been rated with an important severity.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Hardened ImagesphpNot affected
Red Hat Enterprise Linux 10php8.4FixedRHSA-2026:2264902.06.2026
Red Hat Enterprise Linux 10phpFixedRHSA-2026:2338804.06.2026
Red Hat Enterprise Linux 8phpFixedRHSA-2026:2230501.06.2026
Red Hat Enterprise Linux 8phpFixedRHSA-2026:3435401.07.2026
Red Hat Enterprise Linux 9phpFixedRHSA-2026:2214201.06.2026
Red Hat Enterprise Linux 9phpFixedRHSA-2026:2214301.06.2026
Red Hat Enterprise Linux 9phpFixedRHSA-2026:3344930.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2468565php: NULL pointer dereference in SOAP apache:Map decoder with missing <value>

EPSS

Процентиль: 52%
0.0078
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.

CVSS3: 7.5
nvd
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.

msrc
около 2 месяцев назад

NULL pointer dereference in SOAP apache:Map decoder with missing <value>

CVSS3: 7.5
debian
3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

github
3 месяца назад

NULL pointer dereference in SOAP apache:Map decoder with missing <value>

EPSS

Процентиль: 52%
0.0078
Низкий

7.5 High

CVSS3