Php

Php

728 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 30.07.2026 11:22:53
  • Zuletzt bearbeitet 05.08.2026 19:39:54

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9...

  • EPSS 0.52%
  • Veröffentlicht 30.07.2026 11:22:24
  • Zuletzt bearbeitet 05.08.2026 19:40:18

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

  • EPSS 0.47%
  • Veröffentlicht 30.07.2026 11:22:04
  • Zuletzt bearbeitet 05.08.2026 19:40:35

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Medienbericht
  • EPSS 0.28%
  • Veröffentlicht 03.07.2026 20:57:31
  • Zuletzt bearbeitet 08.07.2026 20:11:16

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding o...

  • EPSS 0.35%
  • Veröffentlicht 10.05.2026 04:43:04
  • Zuletzt bearbeitet 24.07.2026 08:10:00

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the X...

  • EPSS 0.47%
  • Veröffentlicht 10.05.2026 04:35:17
  • Zuletzt bearbeitet 24.07.2026 08:10:00

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it mean...

  • EPSS 0.34%
  • Veröffentlicht 10.05.2026 04:28:14
  • Zuletzt bearbeitet 24.07.2026 08:10:00

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized...

Medienbericht
  • EPSS 0.89%
  • Veröffentlicht 10.05.2026 04:19:15
  • Zuletzt bearbeitet 24.07.2026 08:10:00

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. Whe...

  • EPSS 0.2%
  • Veröffentlicht 10.05.2026 04:13:26
  • Zuletzt bearbeitet 24.07.2026 08:10:00

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of servi...

  • EPSS 0.3%
  • Veröffentlicht 10.05.2026 04:07:25
  • Zuletzt bearbeitet 24.07.2026 08:10:00

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the c...