CRITICAL🇵🇱 Wersja polska

CVE-2026-6722

CVSS 9.5v4.0pub. 2026-05-10upd. 2026-07-24

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

🤖 AI Analysis
How it works

The object deduplication mechanism in the SOAP extension stores pointers to PHP objects in a global map without incrementing the reference counter. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary results map, causing the original PHP object to be freed while its pointer (dangling pointer) remains in the map. A subsequent href reference to the freed node copies this invalid pointer to the result. Since PHP string allocations may reuse the freed memory area, an attacker controlling SOAP request content can trigger arbitrary code execution.

Impact

An unauthenticated attacker can achieve remote code execution (RCE) on a server processing malicious SOAP requests, which may lead to complete system compromise and threats to data confidentiality, integrity, and availability.

Mitigation & patch

PHP should be updated as soon as possible to version 8.2.31, 8.3.31, 8.4.21, or 8.5.6 (depending on the branch in use). Until the patch is deployed, consider disabling the SOAP extension (if not required) or restricting access to SOAP endpoints at the firewall level.

Who is affected

PHP versions 8.2.x before 8.2.31, 8.3.x before 8.3.31, 8.4.x before 8.4.21, and 8.5.x before 8.5.6 — affects installations with the SOAP extension enabled.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:Red
  • PHP

    APP
    Php
    8.2.0 – 8.2.31 (excl.)8.3.0 – 8.3.31 (excl.)8.4.0 – 8.4.21 (excl.)8.5.0 – 8.5.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit

CVE-2012-1823CRITICAL9.8⚠ KEVPL ✓same product

RCE w PHP-CGI poprzez wstrzyknięcie opcji wiersza poleceń

CVE-2024-11235CRITICAL9.2PL ✓same product

PHP use-after-free przez __set lub ??= z wyjątkami — RCE

CVE-2022-31631CRITICAL9.1PL ✓same product

PHP PDO SQLite — błędne cytowanie ciągów prowadzące do SQL injection

CVE-2024-11236CRITICAL9.8PL ✓same product

PHP: integer overflow w ldap_escape() prowadzący do out-of-bounds write