Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 15

Количество 15

ubuntu логотип

CVE-2026-7261

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2026-7261

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2026-7261

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2026-7261

около 2 месяцев назад

SoapServer session-persisted object use-after-free via SOAP header fault

EPSS: Низкий
debian логотип

CVE-2026-7261

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-m33r-qmcv-p97q

3 месяца назад

SoapServer session-persisted object use-after-free via SOAP header fault

EPSS: Низкий
fstec логотип

BDU:2026-08445

3 месяца назад

Уязвимость класса SoapServer интерпретатора языка программирования PHP, связанная с использованием памяти после её освобождения, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2091-1

2 месяца назад

Security update for php7

EPSS: Низкий
rocky логотип

RLSA-2026:34354

29 дней назад

Important: php:7.4 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-34354

29 дней назад

ELSA-2026-34354: php:7.4 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-33449

29 дней назад

ELSA-2026-33449: php security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2037-1

2 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1958-1

2 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1957-1

2 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20745-1

3 месяца назад

Security update for php8

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-7261

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 9.8
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-7261

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 5.6
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-7261

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 9.8
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-7261

SoapServer session-persisted object use-after-free via SOAP header fault

0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-7261

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-m33r-qmcv-p97q

SoapServer session-persisted object use-after-free via SOAP header fault

0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-08445

Уязвимость класса SoapServer интерпретатора языка программирования PHP, связанная с использованием памяти после её освобождения, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 9.8
0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2091-1

Security update for php7

2 месяца назад
rocky логотип
RLSA-2026:34354

Important: php:7.4 security update

29 дней назад
oracle-oval логотип
ELSA-2026-34354

ELSA-2026-34354: php:7.4 security update (IMPORTANT)

29 дней назад
oracle-oval логотип
ELSA-2026-33449

ELSA-2026-33449: php security update (IMPORTANT)

29 дней назад
suse-cvrf логотип
SUSE-SU-2026:2037-1

Security update for php8

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1958-1

Security update for php8

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1957-1

Security update for php8

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20745-1

Security update for php8

3 месяца назад

Уязвимостей на страницу