Skip to main content
EPSS 0.2%top 89%

XSS within PHP-FPM status endpoint (CVE-2026-6735)

0
High
Published: 05/12/2026 (05/12/2026, 08:56:02 UTC)
Source: GCVE Database
Product: php

Description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64php-main@aarch64<8.1.2-1ubuntu2.24<8.3.6-0ubuntu0.24.04.9<8.4.11-1ubuntu1.2<8.5.4-0ubuntu1.1>=8.2.0 <8.2.31>=8.3.0 <8.3.31>=8.4.0 <8.4.21>=8.5.0 <8.5.6

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:34:16 UTC

Technical Analysis

The advisory covers a security update for Red Hat Hardened Images RPMs, specifically PHP packages version 8.5.6-1.hum1 for aarch64 and x86_64 architectures. Among the vulnerabilities addressed is CVE-2026-7258, where certain PHP functions such as urldecode() incorrectly pass signed characters to ctype functions, potentially causing negative memory offsets and enabling denial of service conditions. This vulnerability is classified under CWE-839 (Numeric Range Comparison Without Minimum Check) and CWE-79. The advisory notes that mitigation for CVE-2026-7258 is either unavailable or unsuitable for widespread use. The update is intended to fix bugs and enhance the hardened images but does not explicitly list fixed CVEs or patch availability. Red Hat remains the authoritative source for impact and remediation status. No known exploits in the wild are reported.

Potential Impact

The primary impact is a denial of service condition caused by improper handling of signed characters in PHP ctype functions, which can lead to memory access violations. This can make affected PHP applications or systems unavailable. No confidentiality or integrity impacts are explicitly described. The advisory rates the overall severity as medium. There are no reports of active exploitation in the wild.

Mitigation Recommendations

The vendor advisory indicates that mitigation options for the key vulnerability (CVE-2026-7258) are either not available or do not meet Red Hat's criteria for ease of use, applicability, or stability. Users should apply the provided update to the PHP RPM packages as detailed in the advisory to benefit from bug fixes and enhancements. For detailed update instructions, consult the Red Hat Hardened Images update resources. Monitoring Red Hat's official advisories for future fixes or mitigations is recommended. No temporary or alternative mitigations are currently endorsed by Red Hat.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:22142
Cve Count
4
Additional Cves
["CVE-2026-7258","CVE-2026-7262","CVE-2026-7568"]
State
PUBLISHED

Threat ID: 6a1df668e29bf47b50460d22

Added to database: 06/01/2026, 21:15:20 UTC

Last enriched: 08/16/2026, 17:34:16 UTC

Last updated: 09/14/2026, 10:01:33 UTC

Views: 141

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses