NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix (CVE-2025-6491)
A vulnerability in the PHP SOAP extension allows a null pointer dereference when parsing XML data with an overly large XML namespace prefix exceeding 2GB. This issue affects PHP versions prior to 8.1.33, 8.2.29, 8.3.23, and 8.4.10. The flaw may cause server crashes, impacting availability.
AI Analysis
Technical Summary
CVE-2025-6491 is a null pointer dereference vulnerability in the PHP SOAP extension triggered by parsing XML data containing an excessively large (>2GB) XML namespace prefix. This defect affects PHP versions 8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, and 8.4.* before 8.4.10. The vulnerability can cause the PHP process to crash, leading to denial of service conditions on affected servers.
Potential Impact
Successful exploitation results in a null pointer dereference causing the PHP process to crash, which can disrupt service availability. There is no indication of code execution or data compromise from the provided data.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade to PHP versions 8.1.33 or later, 8.2.29 or later, 8.3.23 or later, or 8.4.10 or later to remediate this issue.
NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix (CVE-2025-6491)
Description
A vulnerability in the PHP SOAP extension allows a null pointer dereference when parsing XML data with an overly large XML namespace prefix exceeding 2GB. This issue affects PHP versions prior to 8.1.33, 8.2.29, 8.3.23, and 8.4.10. The flaw may cause server crashes, impacting availability.
Affected software
pkg:bitnami/phpRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-6491 is a null pointer dereference vulnerability in the PHP SOAP extension triggered by parsing XML data containing an excessively large (>2GB) XML namespace prefix. This defect affects PHP versions 8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, and 8.4.* before 8.4.10. The vulnerability can cause the PHP process to crash, leading to denial of service conditions on affected servers.
Potential Impact
Successful exploitation results in a null pointer dereference causing the PHP process to crash, which can disrupt service availability. There is no indication of code execution or data compromise from the provided data.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade to PHP versions 8.1.33 or later, 8.2.29 or later, 8.3.23 or later, or 8.4.10 or later to remediate this issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BIT-php-2025-6491
- Osv Schema Version
- 1.6.2
- Aliases
- ["CVE-2025-6491"]
- Ecosystems
- ["Bitnami"]
- Database Specific Severity
- Medium
Threat ID: 6aa005dcacd9273b49ab6038
Added to database: 09/08/2026, 12:55:56 UTC
Last enriched: 09/08/2026, 13:27:13 UTC
Last updated: 09/10/2026, 19:24:57 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.