Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

github логотип

GHSA-m33r-qmcv-p97q

3 месяца назад

SoapServer session-persisted object use-after-free via SOAP header fault

EPSS: Низкий
ubuntu логотип

CVE-2026-7261

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2026-7261

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2026-7261

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2026-7261

3 месяца назад

SoapServer session-persisted object use-after-free via SOAP header fault

EPSS: Низкий
debian логотип

CVE-2026-7261

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2026-08445

3 месяца назад

Уязвимость класса SoapServer интерпретатора языка программирования PHP, связанная с использованием памяти после её освобождения, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2091-1

3 месяца назад

Security update for php7

EPSS: Низкий
rocky логотип

RLSA-2026:34354

около 2 месяцев назад

Important: php:7.4 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-34354

около 2 месяцев назад

ELSA-2026-34354: php:7.4 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:33449

21 день назад

Important: php security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-33449

около 2 месяцев назад

ELSA-2026-33449: php security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2037-1

3 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1958-1

3 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1957-1

3 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20745-1

3 месяца назад

Security update for php8

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m33r-qmcv-p97q

SoapServer session-persisted object use-after-free via SOAP header fault

0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-7261

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 9.8
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-7261

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 5.6
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-7261

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

CVSS3: 9.8
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-7261

SoapServer session-persisted object use-after-free via SOAP header fault

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-7261

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 9.8
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-08445

Уязвимость класса SoapServer интерпретатора языка программирования PHP, связанная с использованием памяти после её освобождения, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 9.8
0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2091-1

Security update for php7

3 месяца назад
rocky логотип
RLSA-2026:34354

Important: php:7.4 security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-34354

ELSA-2026-34354: php:7.4 security update (IMPORTANT)

около 2 месяцев назад
rocky логотип
RLSA-2026:33449

Important: php security update

21 день назад
oracle-oval логотип
ELSA-2026-33449

ELSA-2026-33449: php security update (IMPORTANT)

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2037-1

Security update for php8

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1958-1

Security update for php8

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1957-1

Security update for php8

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20745-1

Security update for php8

3 месяца назад

Уязвимостей на страницу