7.5
CVE-2026-91765
- EPSS 0.52%
- Veröffentlicht 25.09.2026 20:33:03
- Zuletzt bearbeitet 29.09.2026 21:27:41
- Erkennungen
SOAP: Unbounded Recursion in Server-Side cleanup_xml_node
cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPHP Group
≫
Produkt
PHP
Default Statusunaffected
Version
8.2.*
Version <
8.2.34
Status
affected
Version
8.3.*
Version <
8.3.35
Status
affected
Version
8.4.*
Version <
8.4.26
Status
affected
Version
8.5.*
Version <
8.5.11
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.416 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| PHP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-674 Uncontrolled Recursion
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://github.com/php/php-src/security/advisories/GHSA-rgrp-mwpx-f6rm