VYPR
High severity7.5NVD Advisory· Published May 10, 2026· Updated May 12, 2026

CVE-2026-7263

CVE-2026-7263

Description

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

Affected products

1
  • cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Range: >=8.4.0,<8.4.21

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.