PT-2026-98291 · Php+6 · Php+13

·

CVE-2026-93682

·

Published

2026-09-24

·

Updated

2026-10-01

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An out-of-bounds read occurs in the HTTP stream wrapper when following a redirect where the response contains a Location header with an empty value. The redirect code reads one byte beyond the end of the heap buffer storing the location. A malicious server can leverage the value of this byte to control whether the client is redirected to the host root or the current directory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-104913
BIT-LIBPHP-2026-93682
BIT-PHP-2026-93682
BIT-PHP-MIN-2026-93682
CVE-2026-93682
OPENSUSE-SU-2026:11901-1

Affected Products

Php
Libphp
Php-Min
Php5
Php7.0
Php7.2
Php7.4
Php8
Php8.1
Php8.2
Php8.3
Php8.4
Php8.5
Php83