CVE-2026-7263

Severity CVSS v4.0:
MEDIUM
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
10/05/2026
Last modified:
10/05/2026

Description

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.