Количество 15
Количество 15
CVE-2026-7261
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.
CVE-2026-7261
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.
CVE-2026-7261
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.
CVE-2026-7261
SoapServer session-persisted object use-after-free via SOAP header fault
CVE-2026-7261
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...
GHSA-m33r-qmcv-p97q
SoapServer session-persisted object use-after-free via SOAP header fault
BDU:2026-08445
Уязвимость класса SoapServer интерпретатора языка программирования PHP, связанная с использованием памяти после её освобождения, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
SUSE-SU-2026:2091-1
Security update for php7
RLSA-2026:34354
Important: php:7.4 security update
ELSA-2026-34354
ELSA-2026-34354: php:7.4 security update (IMPORTANT)
ELSA-2026-33449
ELSA-2026-33449: php security update (IMPORTANT)
SUSE-SU-2026:2037-1
Security update for php8
SUSE-SU-2026:1958-1
Security update for php8
SUSE-SU-2026:1957-1
Security update for php8
openSUSE-SU-2026:20745-1
Security update for php8
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-7261 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-7261 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system. | CVSS3: 5.6 | 0% Низкий | 3 месяца назад | |
CVE-2026-7261 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-7261 SoapServer session-persisted object use-after-free via SOAP header fault | 0% Низкий | около 2 месяцев назад | ||
CVE-2026-7261 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ... | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
GHSA-m33r-qmcv-p97q SoapServer session-persisted object use-after-free via SOAP header fault | 0% Низкий | 3 месяца назад | ||
BDU:2026-08445 Уязвимость класса SoapServer интерпретатора языка программирования PHP, связанная с использованием памяти после её освобождения, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
SUSE-SU-2026:2091-1 Security update for php7 | 2 месяца назад | |||
RLSA-2026:34354 Important: php:7.4 security update | 29 дней назад | |||
ELSA-2026-34354 ELSA-2026-34354: php:7.4 security update (IMPORTANT) | 29 дней назад | |||
ELSA-2026-33449 ELSA-2026-33449: php security update (IMPORTANT) | 29 дней назад | |||
SUSE-SU-2026:2037-1 Security update for php8 | 2 месяца назад | |||
SUSE-SU-2026:1958-1 Security update for php8 | 2 месяца назад | |||
SUSE-SU-2026:1957-1 Security update for php8 | 2 месяца назад | |||
openSUSE-SU-2026:20745-1 Security update for php8 | 3 месяца назад |
Уязвимостей на страницу