CVE-2026-6104: CWE-125 Out-of-bounds Read in PHP Group PHP
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.
AI Analysis
Technical Summary
In PHP versions 8.4.* prior to 8.4.21 and 8.5.* prior to 8.5.6, the mbstring extension functions (including mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order()) improperly handle encoding names containing embedded NUL bytes. The vulnerability arises from an incorrect assumption that strncasecmp() returning 0 implies equal string length, which can cause an out-of-bounds read of global memory. This flaw can lead to application crashes or information disclosure. The issue also affects mbstring INI settings such as mbstring.detect_order and mbstring.http_output. Red Hat has issued security advisories and patches addressing this vulnerability in their PHP 8.4 packages.
Potential Impact
Successful exploitation can cause out-of-bounds memory reads, potentially leading to application crashes or disclosure of sensitive information from global memory. The vulnerability affects PHP applications using mbstring functions with attacker-controlled encoding names containing embedded NUL bytes. The CVSS 4.0 base score is 6.3, indicating a medium severity impact with network attack vector, low complexity, and partial impact on confidentiality and availability.
Mitigation Recommendations
A security update fixing this vulnerability is available in PHP versions 8.4.21 and 8.5.6. Users should upgrade affected PHP installations to these or later versions to remediate the issue. Red Hat has released updated PHP 8.4 packages addressing this vulnerability for Red Hat Enterprise Linux 10. No alternative mitigations are indicated in the vendor advisory.
CVE-2026-6104: CWE-125 Out-of-bounds Read in PHP Group PHP
Description
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.
CVSS v4.0
Score 6.3medium
Affected software
pkg:github/php/php-srcRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In PHP versions 8.4.* prior to 8.4.21 and 8.5.* prior to 8.5.6, the mbstring extension functions (including mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order()) improperly handle encoding names containing embedded NUL bytes. The vulnerability arises from an incorrect assumption that strncasecmp() returning 0 implies equal string length, which can cause an out-of-bounds read of global memory. This flaw can lead to application crashes or information disclosure. The issue also affects mbstring INI settings such as mbstring.detect_order and mbstring.http_output. Red Hat has issued security advisories and patches addressing this vulnerability in their PHP 8.4 packages.
Potential Impact
Successful exploitation can cause out-of-bounds memory reads, potentially leading to application crashes or disclosure of sensitive information from global memory. The vulnerability affects PHP applications using mbstring functions with attacker-controlled encoding names containing embedded NUL bytes. The CVSS 4.0 base score is 6.3, indicating a medium severity impact with network attack vector, low complexity, and partial impact on confidentiality and availability.
Mitigation Recommendations
A security update fixing this vulnerability is available in PHP versions 8.4.21 and 8.5.6. Users should upgrade affected PHP installations to these or later versions to remediate the issue. Red Hat has released updated PHP 8.4 packages addressing this vulnerability for Red Hat Enterprise Linux 10. No alternative mitigations are indicated in the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- php
- Date Reserved
- 2026-04-11T04:15:03.938Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-6104","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22649","vendor":"Red Hat"}]
Threat ID: 6a001cdccbff5d86104d92ae
Added to database: 05/10/2026, 05:51:24 UTC
Last enriched: 07/15/2026, 09:35:49 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 138
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.