Количество 33
Количество 33
BDU:2026-06622
Уязвимость функции soap_add_xml_ref() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код
ROS-20260831-80-0007
Уязвимость php 8.5
ROS-20260831-80-0006
Уязвимость php 8.4
ROS-20260831-80-0005
Уязвимость php 8.3
ROS-20260831-80-0004
Уязвимость php
ROS-20260831-73-0006
Уязвимость php 8.4
ROS-20260831-73-0005
Уязвимость php 8.3
ROS-20260831-73-0004
Уязвимость php
ALT-PU-2026-9831
ALT-PU-2026-9831: package `php8.2-soap` update to version 8.2.31-alt1
ALT-PU-2026-8355
ALT-PU-2026-8355: package `php8.2-soap` update to version 8.2.31-alt1
ALT-PU-2026-8952
ALT-PU-2026-8952: package `php8.2` update to version 8.2.31-alt1
ALT-PU-2026-8353
ALT-PU-2026-8353: package `php8.3-soap` update to version 8.3.31-alt1
ALT-PU-2026-8045
ALT-PU-2026-8045: package `php8.3` update to version 8.3.31-alt1
ALT-PU-2026-8043
ALT-PU-2026-8043: package `php8.2` update to version 8.2.31-alt1
CVE-2026-6722
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.
CVE-2026-6722
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.
CVE-2026-6722
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.
CVE-2026-6722
Use-After-Free in SOAP using Apache map
CVE-2026-6722
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...
ALT-PU-2026-8354
ALT-PU-2026-8354: package `php8.4-soap` update to version 8.4.21-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-06622 Уязвимость функции soap_add_xml_ref() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код | CVSS3: 9 | 1% Низкий | 5 месяцев назад | |
ROS-20260831-80-0007 Уязвимость php 8.5 | CVSS3: 9 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-80-0006 Уязвимость php 8.4 | CVSS3: 9 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-80-0005 Уязвимость php 8.3 | CVSS3: 9 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-80-0004 Уязвимость php | CVSS3: 9 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-73-0006 Уязвимость php 8.4 | CVSS3: 9 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-73-0005 Уязвимость php 8.3 | CVSS3: 9 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-73-0004 Уязвимость php | CVSS3: 9 | 1% Низкий | около 1 месяца назад | |
ALT-PU-2026-9831 ALT-PU-2026-9831: package `php8.2-soap` update to version 8.2.31-alt1 | CVSS3: 9.8 | 4 месяца назад | ||
ALT-PU-2026-8355 ALT-PU-2026-8355: package `php8.2-soap` update to version 8.2.31-alt1 | CVSS3: 9.8 | 4 месяца назад | ||
ALT-PU-2026-8952 ALT-PU-2026-8952: package `php8.2` update to version 8.2.31-alt1 | CVSS3: 9.8 | 4 месяца назад | ||
ALT-PU-2026-8353 ALT-PU-2026-8353: package `php8.3-soap` update to version 8.3.31-alt1 | CVSS3: 9.8 | 4 месяца назад | ||
ALT-PU-2026-8045 ALT-PU-2026-8045: package `php8.3` update to version 8.3.31-alt1 | CVSS3: 9.8 | 4 месяца назад | ||
ALT-PU-2026-8043 ALT-PU-2026-8043: package `php8.2` update to version 8.2.31-alt1 | CVSS3: 9.8 | 4 месяца назад | ||
CVE-2026-6722 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution. | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-6722 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution. | CVSS3: 7.7 | 1% Низкий | 5 месяцев назад | |
CVE-2026-6722 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution. | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-6722 Use-After-Free in SOAP using Apache map | 1% Низкий | 4 месяца назад | ||
CVE-2026-6722 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ... | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
ALT-PU-2026-8354 ALT-PU-2026-8354: package `php8.4-soap` update to version 8.4.21-alt1 | CVSS3: 9.8 | 4 месяца назад |
Уязвимостей на страницу