🔐 CVE Alert

CVE-2026-7262

HIGH 7.5

NULL pointer dereference in SOAP apache:Map decoder with missing <value>

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.

CWE CWE-476
Vendor php group
Product php
Published May 10, 2026
Last Updated Jul 15, 2026
Stay Ahead of the Next One

Get instant alerts for php group php

Be the first to know when new high vulnerabilities affecting php group php are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

PHP Group / PHP
8.2.* < 8.2.31 8.3.* < 8.3.31 8.4.* < 8.4.21 8.5.* < 8.5.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/php/php-src/security/advisories/GHSA-hmxp-6pc4-f3vv access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-7262 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2468565 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7262.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:23388 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:22649 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:34354 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:22305 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:22142 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:22143 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33449

Credits

🔍 Ilia Alshanetsky Ilija Tovilo