Null Pointer Dereference in PHP PDO PostgreSQL Driver
CVE-2025-14180
What is CVE-2025-14180?
An issue exists in specific PHP versions when utilizing the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES set to true. Invalid character sequences in prepared statement parameters can lead to a situation where the quoting function PQescapeStringConn returns NULL. This failure triggers a null pointer dereference within the pdo_parse_params() function, potentially resulting in segmentation faults and disrupting the availability of the server. This vulnerability emphasizes the need for developers to ensure proper parameter validation in their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PHP 8.1.*
PHP 8.1.* < 8.1.34
PHP 8.2.* < 8.2.30
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
