DoS attack via DOMNode::C14N()
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.3epss 0.4%
exploitation probability
0.4%top 72% of all CVEs
observed exploitation
nono source reports it
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/AU:Y/RE:M/U:Amber
Affected products
PHP Group · PHPReferences
https://access.redhat.com/errata/RHSA-2026:22649https://access.redhat.com/security/cve/CVE-2026-7263https://bugzilla.redhat.com/show_bug.cgi?id=2468572https://github.com/php/php-src/security/advisories/GHSA-4jhr-8w89-j733https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7263.json