CVE-2026-7263

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

History

12 May 2026, 17:35

Type Values Removed Values Added
CPE cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Php
Php php
References () https://github.com/php/php-src/security/advisories/GHSA-4jhr-8w89-j733 - () https://github.com/php/php-src/security/advisories/GHSA-4jhr-8w89-j733 - Vendor Advisory

10 May 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-10 06:16

Updated : 2026-05-12 17:35


NVD link : CVE-2026-7263

Mitre link : CVE-2026-7263

CVE.ORG link : CVE-2026-7263


JSON object : View

Products Affected

php

  • php
CWE
CWE-404

Improper Resource Shutdown or Release

CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')