CVEFinder.io

CVE-2026-6722

β›” critical
πŸ” Scan for this CVE
Summary

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global mapΒ without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can

Description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global mapΒ without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

CVSS Score
9.8
Critical
EPSS Score
0.9
Exploit Probability
Published Date
2026-05-10
First Seen: 2026-05-11
πŸ“Š Relative Risk Intelligence

This CVE is Very High Risk - more severe than 90.5% of all 350,976 vulnerabilities in our database.

#33,444
Top 10% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: May 11, 2026
πŸ” Exploitation Status
None
No known exploits
βš™οΈ Automatable
NO
Requires human interaction
πŸ’₯ Technical Impact
Total
Complete system compromise possible
πŸ† Discovered By
brettgervasoni (reporter) Ilija Tovilo (remediation developer) Nora Dossche (remediation reviewer)
SSVC data provided by CISA
Last Modified 2026-07-24
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:Red
CWE IDs (Weakness Types)

πŸ“¦ Affected Products 4

πŸ”— References 11

πŸ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-17543 β›” critical 9.8 0.5 Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versionsΒ ... 2026-07-30
CVE-2026-17544 β›” critical 9.8 0.5 Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions... 2026-07-30
CVE-2026-7260 πŸ”Ά medium 5.5 0.2 Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP ... 2026-07-30
CVE-2026-14355 πŸ”Ά medium 5.6 0.3 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo... 2026-07-03
CVE-2025-14179 β›” critical 9.8 0.4 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird ... 2026-05-10
CVE-2026-6735 πŸ”Ά medium 6.1 0.2 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanit... 2026-05-10
These CVEs affect the same products