Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7263

Опубликовано: 10 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

A flaw was found in PHP. The DOMNode::C14N() method may incorrectly process XML data due to the improper removal of an xmlns attribute from the underlying libxml2 data structure, corrupting the linked list representing the XML document and causing an infinite loop. This issue can lead to excessive resource consumption, eventually resulting in a denial of service in the processing application.

Отчет

To exploit this issue, an attacker needs to be able to supply specially crafted XML data to be processed by the DOMNode::C14N() method. This can trigger an infinite loop, causing excessive resource consumption, eventually resulting in a denial of service in the program processing the data. As this flaw allows an unauthenticated and remote attacker to cause a denial of service, it has been rated with an important severity.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10phpNot affected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Enterprise Linux 8php:7.4/phpNot affected
Red Hat Enterprise Linux 8php:8.2/phpNot affected
Red Hat Enterprise Linux 9phpNot affected
Red Hat Enterprise Linux 9php:8.2/phpNot affected
Red Hat Enterprise Linux 9php:8.3/phpNot affected
Red Hat Hardened ImagesphpNot affected
Red Hat Enterprise Linux 10php8.4FixedRHSA-2026:2264902.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2468572php: denial of service via DOMNode::C14N()

EPSS

Процентиль: 28%
0.00353
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

CVSS3: 7.5
nvd
3 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

CVSS3: 7.5
debian
3 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C ...

github
3 месяца назад

DoS attack via DOMNode::C14N()

rocky
около 2 месяцев назад

Important: php8.4 security update

EPSS

Процентиль: 28%
0.00353
Низкий

7.5 High

CVSS3