High severity7.5NVD Advisory· Published May 10, 2026· Updated Jul 24, 2026
CVE-2026-7263
CVE-2026-7263
Description
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31- osv-coords29 versionspkg:bitnami/libphppkg:bitnami/phppkg:bitnami/php-minpkg:rpm/almalinux/php8.4pkg:rpm/almalinux/php8.4-bcmathpkg:rpm/almalinux/php8.4-clipkg:rpm/almalinux/php8.4-commonpkg:rpm/almalinux/php8.4-dbapkg:rpm/almalinux/php8.4-dbgpkg:rpm/almalinux/php8.4-develpkg:rpm/almalinux/php8.4-embeddedpkg:rpm/almalinux/php8.4-enchantpkg:rpm/almalinux/php8.4-ffipkg:rpm/almalinux/php8.4-fpmpkg:rpm/almalinux/php8.4-gdpkg:rpm/almalinux/php8.4-gmppkg:rpm/almalinux/php8.4-intlpkg:rpm/almalinux/php8.4-ldappkg:rpm/almalinux/php8.4-mbstringpkg:rpm/almalinux/php8.4-mysqlndpkg:rpm/almalinux/php8.4-odbcpkg:rpm/almalinux/php8.4-opcachepkg:rpm/almalinux/php8.4-pdopkg:rpm/almalinux/php8.4-pgsqlpkg:rpm/almalinux/php8.4-processpkg:rpm/almalinux/php8.4-snmppkg:rpm/almalinux/php8.4-soappkg:rpm/almalinux/php8.4-xmlpkg:rpm/opensuse/php8&distro=openSUSE%20Tumbleweed
>= 8.4.0, < 8.4.21+ 28 more
- (no CPE)range: >= 8.4.0, < 8.4.21
- (no CPE)range: >= 8.4.0, < 8.4.21
- (no CPE)range: >= 8.4.0, < 8.4.21
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.4.21-1.el10_2
- (no CPE)range: < 8.5.6-1.1
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.