CVE-2026-7259

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

History

12 May 2026, 17:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Php
Php php
References () https://github.com/php/php-src/security/advisories/GHSA-wm6j-2649-pv75 - () https://github.com/php/php-src/security/advisories/GHSA-wm6j-2649-pv75 - Vendor Advisory
CPE cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

10 May 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-10 05:16

Updated : 2026-05-12 17:40


NVD link : CVE-2026-7259

Mitre link : CVE-2026-7259

CVE.ORG link : CVE-2026-7259


JSON object : View

Products Affected

php

  • php
CWE
CWE-476

NULL Pointer Dereference