🔐 CVE Alert

CVE-2026-7258

UNKNOWN 0.0

Out-of-bounds read in urldecode() on NetBSD

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
2th

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.

CWE CWE-125
Vendor php group
Product php
Published May 10, 2026
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for php group php

Be the first to know when new unknown vulnerabilities affecting php group php are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

PHP Group / PHP
8.2.* < 8.2.31 8.3.* < 8.3.31 8.4.* < 8.4.21 8.5.* < 8.5.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/php/php-src/security/advisories/GHSA-m8rr-4c36-8gq4

Credits

🔍 xfourj Ilija Tovilo