CVE Vulnerabilities

CVE-2026-7262

NULL Pointer Dereference

Published: May 10, 2026 | Modified: May 12, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp8.2.0 (including)8.2.31 (excluding)
PhpPhp8.3.0 (including)8.3.31 (excluding)
PhpPhp8.4.0 (including)8.4.21 (excluding)
PhpPhp8.5.0 (including)8.5.6 (excluding)
Red Hat Enterprise Linux 10RedHatphp8.4-0:8.4.21-1.el10_2*
Red Hat Enterprise Linux 10RedHatphp-0:8.3.31-1.el10_2*
Red Hat Enterprise Linux 8RedHatphp:8.2-8100020260521052503.f7998665*
Red Hat Enterprise Linux 9RedHatphp:8.3-9080020260521113736.9*
Red Hat Enterprise Linux 9RedHatphp:8.2-9080020260521080715.9*
Php7.0Ubuntuesm-infra/xenial*
Php8.1Ubuntujammy*
Php8.3Ubuntunoble*
Php8.3Ubuntuupstream*
Php8.4Ubuntuquesting*
Php8.4Ubuntuupstream*
Php8.5Ubuntudevel*
Php8.5Ubunturesolute*
Php8.5Ubuntuupstream*

Potential Mitigations

References