PT-2026-39443 · Php+3 · Php+3

·

CVE-2025-14179

·

Published

2026-02-11

·

Updated

2026-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions 8.2.0 through 8.2.30 PHP versions 8.3.0 through 8.3.30 PHP versions 8.4.0 through 8.4.20 PHP versions 8.5.0 through 8.5.5
Description The PDO Firebird driver improperly handles NUL bytes during the preparation of SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied using the strncat() function, which terminates at the NUL byte. This action drops the closing quote, causing subsequent SQL tokens to be interpreted as part of the string. This behavior enables SQL injection when attacker-controlled values are processed via the PDO::quote() function and embedded in SQL statements.
Recommendations Update to version 8.2.31 or later. Update to version 8.3.31 or later. Update to version 8.4.21 or later. Update to version 8.5.6 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-86358
BDU:2026-01640
BIT-LIBPHP-2025-14179
BIT-PHP-2025-14179
BIT-PHP-MIN-2025-14179
CVE-2025-14179
OESA-2026-2342
OESA-2026-2343
OESA-2026-2344
OESA-2026-2420
OESA-2026-2421
OPENSUSE-SU-2026:10747-1
USN-8336-1
USN-8513-1

Affected Products

Linuxmint
Php
Red Os
Ubuntu