SOAP Server Vulnerability in PHP by The PHP Group
CVE-2026-7262
2.9LOW
What is CVE-2026-7262?
A vulnerability exists in PHP versions where an error in the decoding process of a SOAP server with a typemap can lead to a NULL pointer dereference. This issue arises when handling a missing value element, resulting in a segmentation fault. Consequently, an unauthenticated remote attacker can exploit this flaw to crash the PHP SOAP server, leading to a denial of service. To ensure security, it is crucial to update to the latest PHP versions that address this vulnerability.
Affected Version(s)
PHP 8.2.*
PHP 8.2.* < 8.2.31
PHP 8.3.* < 8.3.31
