PHP 8.4.x < 8.4.26 Multiple Vulnerabilities

medium Web App Scanning Plugin ID 115551

Synopsis

PHP 8.4.x < 8.4.26 Multiple Vulnerabilities

Description

According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.34, 8.3.x prior to 8.3.35, 8.4.x prior to 8.4.26, or 8.5.x prior to 8.5.11. It is, therefore, affected by multiple vulnerabilities:

- Various packet overreads in the MySQLnd wire protocol implementation. (CVE-2025-1218)

- Integer overflow leading to a buffer overflow in SOAP HTTP parsing. (CVE-2025-14181)

- Integer overflow in phar_tar_number() in Phar allowing TAR archive entry injection. (CVE-2026-6103)

- Reserved device names are not rejected before file and stream I/O on Windows. (CVE-2026-17545)

- Unbounded recursion in server-side cleanup_xml_node() in SOAP. (CVE-2026-91765)

- Cross-origin credential leak in HTTP stream wrapper redirects. (CVE-2026-91766)

- Heap buffer overflow in php_openssl_matches_wildcard_name() in OpenSSL on a crafted server certificate wildcard CN. (CVE-2026-91767)

- IPv6 ACL bypass in FPM FastCGI listen.allowed_clients due to partial address comparison. (CVE-2026-91768)

- TLS hostname verification in OpenSSL falls back to CN after a SAN mismatch. (CVE-2026-91769)

- Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL. (CVE-2026-92842)

- Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header. (CVE-2026-93682)

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to PHP version 8.4.26 or later.

See Also

https://www.php.net/ChangeLog-8.php#8.4.26

Plugin Details

Severity: Medium

ID: 115551

Type: Version Based

Published: 10/2/2026

Updated: 10/2/2026

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.35

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-91765

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2026-17545

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:H

CVSS Score Source: CVE-2026-17545

Vulnerability Information

CPE: cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/21/2026

Reference Information

CVE: CVE-2025-1218, CVE-2025-14181, CVE-2026-17545, CVE-2026-6103, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842, CVE-2026-93682

CWE: 1023, 122, 125, 190, 200, 297, 522, 67, 674

OWASP: 2010-A4, 2010-A6, 2010-A9, 2013-A4, 2013-A5, 2013-A6, 2013-A9, 2017-A3, 2017-A5, 2017-A6, 2017-A9, 2021-A1, 2021-A4, 2021-A6, 2021-A7, 2025-A1, 2025-A6, 2025-A7

WASC: Buffer Overflow, Improper Input Handling, Information Leakage, Insufficient Authorization, Insufficient Transport Layer Protection, Integer Overflows

CAPEC: 102, 116, 13, 169, 22, 224, 230, 231, 285, 287, 290, 291, 292, 293, 294, 295, 296, 297, 298, 299, 300, 301, 302, 303, 304, 305, 306, 307, 308, 309, 310, 312, 313, 317, 318, 319, 320, 321, 322, 323, 324, 325, 326, 327, 328, 329, 330, 472, 474, 497, 50, 508, 509, 540, 551, 555, 560, 561, 573, 574, 575, 576, 577, 59, 60, 600, 616, 643, 644, 645, 646, 651, 652, 653, 79, 92

DISA STIG: APSC-DV-000460, APSC-DV-001810, APSC-DV-002590, APSC-DV-002630, APSC-DV-003235

HIPAA: 164.306(a)(1), 164.306(a)(2)

ISO: 27001-A.10.1.2, 27001-A.12.6.1, 27001-A.14.2.5, 27001-A.9.2.1, 27001-A.9.2.4, 27001-A.9.3.1, 27001-A.9.4.3

NIST: sp800_53-CM-6b, sp800_53-IA-5, sp800_53-SC-12, sp800_53-SI-10, sp800_53-SI-15, sp800_53-SI-16

OWASP API: 2019-API7, 2023-API8

OWASP ASVS: 4.0.2-14.2.1, 4.0.2-8.3.4, 4.0.2-9.2.1

PCI-DSS: 3.2-6.2, 3.2-6.5, 3.2-6.5.10, 3.2-6.5.2, 3.2-6.5.4, 3.2-6.5.8