Vulnerabilidades en PHP Group

102 resultados
Análisis Vexday

O PHP Group acumula 88 CVEs catalogadas, das quais 8 são de severidade crítica e 3 contam com prova de conceito pública disponível, o que facilita a exploração por agentes com capacidade técnica limitada. A taxa de exploração ativa — 1,14% das CVEs confirmadas no catálogo KEV da CISA — é 2,5 vezes superior à média geral do catálogo, sinalizando que vulnerabilidades no PHP atraem atenção consistente de atores mal-intencionados. O caso mais preocupante no momento é CVE-2024-4577, que registra EPSS de 0,9999 — praticamente certeza estatística de exploração ativa —, exigindo prioridade máxima de correção em ambientes que ainda não aplicaram o patch correspondente. O surgimento de 10 novas CVEs nos últimos 90 dias, combinado com CWE-125 (leitura fora dos limites de buffer) como falha mais recorrente, indica que a superfície de ataque permanece em expansão e requer monitoramento contínuo.

CVE-2025-14177MEDIUMInformation Leak of Memory in getimagesizeEPSS 0.5%CVE-2024-9026LOWPHP-FPM logs from children may be alteredEPSS 0.5%CVE-2025-1734MEDIUMStreams HTTP wrapper does not fail for headers with invalid name and no colonEPSS 0.5%CVE-2025-14178MEDIUMHeap buffer overflow in array_merge()EPSS 0.5%CVE-2025-14179HIGHSQL injection in pdo_firebird via NUL bytes in quoted stringsEPSS 0.4%CVE-2026-17544HIGHOut-of-bounds write in bccomp() via crafted operand and scaleEPSS 0.4%CVE-2026-7258MEDIUMOut-of-bounds read in urldecode() on NetBSDEPSS 0.4%CVE-2026-7259LOWNull pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()EPSS 0.3%CVE-2026-17543HIGHSQL injection in ext-pgsql via E'...' backslash breakoutEPSS 0.3%CVE-2026-6735HIGHXSS within PHP-FPM status endpointEPSS 0.3%CVE-2026-7260MEDIUMStack overflow in phar with circular symlinksEPSS 0.1%CVE-2026-91766MEDIUMCross-origin credential leak in HTTP stream wrapper redirectsEPSS —CVE-2026-91767MEDIUMHeap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CNEPSS —CVE-2026-93682MEDIUMOut-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location headerEPSS —CVE-2025-14181MEDIUMInteger overflow to buffer overflow in soap HTTP parsingEPSS —CVE-2026-91768MEDIUMIPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)EPSS —CVE-2026-91765HIGHSOAP: Unbounded Recursion in Server-Side cleanup_xml_nodeEPSS —CVE-2026-17545MEDIUMPHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoSEPSS —CVE-2026-91769MEDIUMTLS Hostname Verification Falls Back to CN After SAN MismatchEPSS —CVE-2026-92842MEDIUMOOB read / info leak in convert.* stream filters when line-break-chars contains NULEPSS —