Out-of-Bounds Write Vulnerability in PHP Affects Multiple Versions
CVE-2026-17544
8.1HIGH
What is CVE-2026-17544?
A vulnerability exists in PHP that allows an attacker to manipulate input to the bccomp() function, potentially leading to out-of-bounds write conditions. This flaw can cause significant issues, including stack and heap corruption, in various PHP versions, notably impacting those prior to their respective secure updates. It's crucial for developers and system administrators to review their PHP versions and apply necessary updates to mitigate these risks.
Affected Version(s)
PHP 8.4.* < 8.4.24
PHP 8.5.* < 8.5.9
References
CVSS V4
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Recep Asan
Ilija Tovilo - The PHP Foundation
Saki Takamachi - The PHP Foundation
