CVE Vulnerabilities

CVE-2026-7259

NULL Pointer Dereference

Published: May 10, 2026 | Modified: May 12, 2026
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp8.2.0 (including)8.2.31 (excluding)
PhpPhp8.3.0 (including)8.3.31 (excluding)
PhpPhp8.4.0 (including)8.4.21 (excluding)
PhpPhp8.5.0 (including)8.5.6 (excluding)
Red Hat Enterprise Linux 10RedHatphp-0:8.3.31-1.el10_2*
Php7.0Ubuntuesm-infra/xenial*
Php8.1Ubuntujammy*
Php8.3Ubuntunoble*
Php8.3Ubuntuupstream*
Php8.4Ubuntuquesting*
Php8.4Ubuntuupstream*
Php8.5Ubuntudevel*
Php8.5Ubunturesolute*
Php8.5Ubuntuupstream*

Potential Mitigations

References