LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-7263

php · php

Published
CVSS7.5
Severityhigh
WeaknessCWE-404
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-7263

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-7263.