Logo
vulnerabilityCVE-2026-7261
Name
CVE-2026-7261
Source
NVD ( link)Debian ( link)
Description
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
php8
Exploitable

Vulnerability Ratings#


6.3
CVSSv4
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
8.3.31
Not Affected
buildroot
master
8.5.7
Not Affected
openwrt
openwrt-25.12
8.4.21-r1
Not Affected
yocto
kirkstone
8.1.34
Not Affected
yocto
master
8.5.7
Not Affected
yocto
scarthgap
8.2.31
Not Affected