CVE-2026-7260
Stack overflow in phar with circular symlinks
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
| CWE | CWE-121 |
| Vendor | php group |
| Product | php |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for php group php
Be the first to know when new unknown vulnerabilities affecting php group php are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
PHP Group / PHP
8.2.* < 8.2.33 8.3.* < 8.3.33 8.4.* < 8.4.24 8.5.* < 8.5.9
References
Credits
Calvin Young - eWalker Consulting (HK) Limited Enoch Chow - Isomorph Cyber Jakub Zelenka - The PHP Foundation