Home

Description

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

PUBLISHED Reserved 2026-04-28 | Published 2026-05-10 | Updated 2026-05-10 | Assigner php




MEDIUM: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/AU:Y/RE:M/U:Amber

Problem types

CWE-404 Improper Resource Shutdown or Release

CWE-835 Loop with unreachable exit condition ('infinite loop')

Product status

Default status
unaffected

8.4.* (semver) before 8.4.21
affected

8.5.* (semver) before 8.5.6
affected

Credits

Nikita Sveshnikov (Positive Technologies) finder

Ilija Tovilo remediation reviewer

References

github.com/...hp-src/security/advisories/GHSA-4jhr-8w89-j733 vendor-advisory

cve.org (CVE-2026-7263)

nvd.nist.gov (CVE-2026-7263)

Download JSON