PT-2026-99112 · Php · Php

·

CVE-2026-17545

·

Published

2026-09-25

·

Updated

2026-09-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions PHP (affected versions not specified)
Description On Windows, filesystem and stream APIs fail to reject reserved device names when they are part of a path. These reserved names include CON, PRN, AUX, NUL, COM1 through COM9, LPT1 through LPT9, CONIN$, and CONOUT$. Consequently, an attacker-controlled filename can reach the CreateFileW() function and open a device instead of a standard file. This behavior can lead to a Denial of Service (DoS) by blocking or hanging requests and exhausting worker processes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17545
OPENSUSE-SU-2026:11901-1

Affected Products

Php