CVE-2025-1218
Various packet overreads in mysqlnd_writeprotocol.c
CVSS Score
3.4
EPSS Score
0.0%
EPSS Percentile
0th
The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.
| CWE | CWE-122 |
| Vendor | php group |
| Product | php |
| Published | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for php group php
Be the first to know when new low vulnerabilities affecting php group php are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
PHP Group / PHP
8.2.* < 8.2.34 8.3.* < 8.3.35 8.4.* < 8.4.26 8.5.* < 8.5.11
References
Credits
๐ Nora Dossche ๐ @bao00065 (GitHub) ๐ @cxxz16 (GitHub) ๐ @TristanInSec (GitHub) ๐ @OSTIF-Derek (GitHub) ๐ @HO-9 (GitHub) Jakub Zelenka Nora Dossche Alexandre Daubois