XSS within PHP-FPM status endpoint (CVE-2026-6735)
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
AI Analysis
Technical Summary
The advisory covers a security update for Red Hat Hardened Images RPMs, specifically PHP packages version 8.5.6-1.hum1 for aarch64 and x86_64 architectures. Among the vulnerabilities addressed is CVE-2026-7258, where certain PHP functions such as urldecode() incorrectly pass signed characters to ctype functions, potentially causing negative memory offsets and enabling denial of service conditions. This vulnerability is classified under CWE-839 (Numeric Range Comparison Without Minimum Check) and CWE-79. The advisory notes that mitigation for CVE-2026-7258 is either unavailable or unsuitable for widespread use. The update is intended to fix bugs and enhance the hardened images but does not explicitly list fixed CVEs or patch availability. Red Hat remains the authoritative source for impact and remediation status. No known exploits in the wild are reported.
Potential Impact
The primary impact is a denial of service condition caused by improper handling of signed characters in PHP ctype functions, which can lead to memory access violations. This can make affected PHP applications or systems unavailable. No confidentiality or integrity impacts are explicitly described. The advisory rates the overall severity as medium. There are no reports of active exploitation in the wild.
Mitigation Recommendations
The vendor advisory indicates that mitigation options for the key vulnerability (CVE-2026-7258) are either not available or do not meet Red Hat's criteria for ease of use, applicability, or stability. Users should apply the provided update to the PHP RPM packages as detailed in the advisory to benefit from bug fixes and enhancements. For detailed update instructions, consult the Red Hat Hardened Images update resources. Monitoring Red Hat's official advisories for future fixes or mitigations is recommended. No temporary or alternative mitigations are currently endorsed by Red Hat.
XSS within PHP-FPM status endpoint (CVE-2026-6735)
Description
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The advisory covers a security update for Red Hat Hardened Images RPMs, specifically PHP packages version 8.5.6-1.hum1 for aarch64 and x86_64 architectures. Among the vulnerabilities addressed is CVE-2026-7258, where certain PHP functions such as urldecode() incorrectly pass signed characters to ctype functions, potentially causing negative memory offsets and enabling denial of service conditions. This vulnerability is classified under CWE-839 (Numeric Range Comparison Without Minimum Check) and CWE-79. The advisory notes that mitigation for CVE-2026-7258 is either unavailable or unsuitable for widespread use. The update is intended to fix bugs and enhance the hardened images but does not explicitly list fixed CVEs or patch availability. Red Hat remains the authoritative source for impact and remediation status. No known exploits in the wild are reported.
Potential Impact
The primary impact is a denial of service condition caused by improper handling of signed characters in PHP ctype functions, which can lead to memory access violations. This can make affected PHP applications or systems unavailable. No confidentiality or integrity impacts are explicitly described. The advisory rates the overall severity as medium. There are no reports of active exploitation in the wild.
Mitigation Recommendations
The vendor advisory indicates that mitigation options for the key vulnerability (CVE-2026-7258) are either not available or do not meet Red Hat's criteria for ease of use, applicability, or stability. Users should apply the provided update to the PHP RPM packages as detailed in the advisory to benefit from bug fixes and enhancements. For detailed update instructions, consult the Red Hat Hardened Images update resources. Monitoring Red Hat's official advisories for future fixes or mitigations is recommended. No temporary or alternative mitigations are currently endorsed by Red Hat.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:22142
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-7258","CVE-2026-7262","CVE-2026-7568"]
- State
- PUBLISHED
Threat ID: 6a1df668e29bf47b50460d22
Added to database: 06/01/2026, 21:15:20 UTC
Last enriched: 08/16/2026, 17:34:16 UTC
Last updated: 09/14/2026, 10:01:33 UTC
Views: 141
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.