PT-2026-39446 · Php+2 · Php+2

·

CVE-2026-7258

·

Published

2026-05-06

·

Updated

2026-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions 8.2.0 through 8.2.30 PHP versions 8.3.0 through 8.3.30 PHP versions 8.4.0 through 8.4.20 PHP versions 8.5.0 through 8.5.5
Description Certain functions, including urldecode(), pass signed characters to ctype functions such as isxdigit(). On systems utilizing default signed characters and optimized table-lookup ctype functions, such as NetBSD, this behavior can result in accessing an array with a negative offset, potentially triggering a denial of service.
Recommendations Update PHP version 8.2.x to 8.2.31 Update PHP version 8.3.x to 8.3.31 Update PHP version 8.4.x to 8.4.21 Update PHP version 8.5.x to 8.5.6

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:22142
ALSA-2026:22143
ALSA-2026:22305
ALSA-2026:22649
ALSA-2026:23388
ALSA-2026:33449
ALSA-2026:34354
AZL-86346
BDU:2026-08591
BIT-LIBPHP-2026-7258
BIT-PHP-2026-7258
BIT-PHP-MIN-2026-7258
CVE-2026-7258
GHSA-M8RR-4C36-8GQ4
OESA-2026-2342
OESA-2026-2343
OESA-2026-2344
OESA-2026-2420
OESA-2026-2421
OPENSUSE-SU-2026:10747-1
OPENSUSE-SU-2026:20745-1
RHSA-2026:14125
RHSA-2026:23388
RHSA-2026:33449
RHSA-2026:34354
SUSE-SU-2026:1957-1
SUSE-SU-2026:1958-1
SUSE-SU-2026:2037-1
SUSE-SU-2026:2091-1
SUSE-SU-2026:21612-1

Affected Products

Php
Red Os
Rocky Linux