Skip to main content

Threats Tagged 'cve-2026-7259'

View all threats tagged with 'cve-2026-7259'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-7259

Threats Tagged 'cve-2026-7259'

Click on any threat for detailed analysis and mitigation recommendations

0

Multiple security vulnerabilities affecting PHP 8.2 on Red Hat Enterprise Linux 8 have been addressed in a security update. These include a denial of service via improper handling of signed characters in ctype functions, a cross-site scripting vulnerability in PHP-FPM due to improper URL sanitation, a NULL pointer dereference in the SOAP apache:Map decoder, and a signed integer overflow in the metaphone() function. The update is rated as important by Red Hat Product Security. No CVSS scores are provided in the advisory. The vulnerabilities affect PHP 8.2 packages distributed with Red Hat Enterprise Linux 8.

Join the discussion
0

This security update for PHP 8 addresses multiple vulnerabilities including SQL injection, out-of-bounds reads, use-after-free, cross-site scripting (XSS), denial of service, memory corruption, information disclosure, and infinite loops. The update also includes an upgrade to PHP version 8.4.21. These issues affect various components such as the PDO Firebird driver, mbstring encoding functions, SOAP handling, PHP-FPM status page, ctype functions, and XML processing.

Join the discussion

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().

Join the discussion
0

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

Join the discussion

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

Join the discussion

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cve-2026-7259
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses