PT-2026-66463 · Php+2 · Php+2
CVE-2026-7260
·
Published
2026-07-30
·
Updated
2026-09-10
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PHP versions 8.2.0 through 8.2.32
PHP versions 8.3.0 through 8.3.32
PHP versions 8.4.0 through 8.4.23
PHP versions 8.5.0 through 8.5.8
Description
Circular symbolic links in phar archives can cause unbounded recursion, which exhausts the C stack and leads to a crash of the PHP process.
Recommendations
Update PHP version 8.2.x to 8.2.33
Update PHP version 8.3.x to 8.3.33
Update PHP version 8.4.x to 8.4.24
Update PHP version 8.5.x to 8.5.9
Fix
DoS
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php
Rocky Linux
Ubuntu