Threats Tagged 'cve-2026-7260'
View all threats tagged with 'cve-2026-7260'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-7260'
Click on any threat for detailed analysis and mitigation recommendations
Multiple security vulnerabilities have been identified and fixed in PHP packages distributed by Red Hat for Red Hat Enterprise Linux 8 and 9. These include a memory corruption issue in the OpenSSL extension (CVE-2026-14355), an SQL injection vulnerability in the PostgreSQL extension due to improper backslash escaping (CVE-2026-17543), and a denial of service vulnerability caused by circular symbolic links in phar archives (CVE-2026-7260). The vulnerabilities affect PHP versions 7.4 and 8.0 as packaged in Red Hat Enterprise Linux. Red Hat has released updated packages with backported fixes for these issues. The overall security impact is rated low to important depending on the PHP version and specific vulnerability. Join the discussion | GCVE Database | 08/31/2026, 07:03:12 UTC Added: 08/31/2026, 15:42:48 UTC |
Red Hat has issued a security advisory for PHP 8.2 addressing two vulnerabilities: a SQL injection vulnerability in the ext-pgsql extension due to improper backslash escaping (CVE-2026-17543) and a denial of service vulnerability caused by circular symbolic links in phar archives (CVE-2026-7260). The update rebases PHP to version 8.2.33 to fix these issues. The advisory rates the security impact as Important and affects Red Hat Enterprise Linux 8 and related variants. Join the discussion | GCVE Database | 08/20/2026, 16:43:22 UTC Added: 08/31/2026, 15:42:49 UTC |
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9. Join the discussion | GCVE Database | 08/17/2026, 05:53:44 UTC Added: 08/31/2026, 15:42:49 UTC |
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9. Join the discussion | GCVE Database | 08/17/2026, 05:53:35 UTC Added: 08/06/2026, 18:17:15 UTC |
CVE-2026-7260 is a stack-based buffer overflow vulnerability in PHP caused by circular symbolic links in phar archives. This flaw can trigger unbounded recursion, exhausting the C stack and crashing the PHP process. It affects PHP versions prior to 8.2.33, 8.3.33, 8.4.24, and 8.5.9. The vulnerability has a medium severity rating with a CVSS score of 5.4. No official patch or remediation level is currently confirmed in the provided data. Join the discussion | CVE Database V5 | 07/30/2026, 12:19:00 UTC Added: 07/30/2026, 11:37:38 UTC |
Showing 1 to 5 of 5 results