🔐 CVE Alert

CVE-2026-6722

HIGH 7.7

Use-After-Free in SOAP using Apache map

CVSS Score
7.7
EPSS Score
0.7%
EPSS Percentile
51th

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

CWE CWE-416
Vendor php group
Product php
Published May 10, 2026
Last Updated Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for php group php

Be the first to know when new high vulnerabilities affecting php group php are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

PHP Group / PHP
8.2.* < 8.2.31 8.3.* < 8.3.31 8.4.* < 8.4.21 8.5.* < 8.5.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/php/php-src/security/advisories/GHSA-85c2-q967-79q5 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-6722 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2468560 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6722.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:23388 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:22649 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:34354 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:22305 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:22142 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:22143 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33449

Credits

🔍 brettgervasoni Ilija Tovilo Nora Dossche