{"schema_version":1,"title":"Php vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in Php: 9 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-92842, was published on 25 September 2026.","url":"https://junglewise.ai/threats/technologies/php-php","json_url":"https://junglewise.ai/threats/technologies/php-php.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/php-php","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":9,"critical":0,"exploited":0,"last_7_days":9,"last_30_days":9,"last_90_days":9,"last_365_days":9},"latest":[{"cve":"CVE-2026-92842","cvss":5.9,"slug":"cve-2026-92842-the-convert-base64-encode-convert-quoted-printable-encode-and","title":"PHP stream filter heap information leak with NUL bytes in line-break-chars","severity":"medium","exploited":false,"published_at":"2026-09-25T22:18:49.943+00:00","url":"https://junglewise.ai/threats/cve-2026-92842-the-convert-base64-encode-convert-quoted-printable-encode-and"},{"cve":"CVE-2026-91769","cvss":4.3,"slug":"cve-2026-91769-php-s-openssl-stream-peer-verification-checks-the-certificate-s","title":"PHP OpenSSL stream peer verification certificate validation bypass","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:24.913+00:00","url":"https://junglewise.ai/threats/cve-2026-91769-php-s-openssl-stream-peer-verification-checks-the-certificate-s"},{"cve":"CVE-2026-91767","cvss":6.5,"slug":"cve-2026-91767-php-openssl-matches-wildcard-name-in-ext-openssl-xp-ssl-c","title":"PHP OpenSSL heap-buffer overflow in wildcard certificate name matching","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:24.793+00:00","url":"https://junglewise.ai/threats/cve-2026-91767-php-openssl-matches-wildcard-name-in-ext-openssl-xp-ssl-c"},{"cve":"CVE-2026-91766","cvss":5.9,"slug":"cve-2026-91766-when-the-http-stream-wrapper-follows-a-redirect-it-forwards-the","title":"PHP HTTP stream wrapper credential leak on cross-origin redirect","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:24.673+00:00","url":"https://junglewise.ai/threats/cve-2026-91766-when-the-http-stream-wrapper-follows-a-redirect-it-forwards-the"},{"cve":"CVE-2026-91765","cvss":7.5,"slug":"cve-2026-91765-cleanup-xml-node-in-the-soap-xml-parser-recurses-once-per-xml","title":"PHP SOAP XML parser unbounded recursion denial of service","severity":"high","exploited":false,"published_at":"2026-09-25T21:17:24.55+00:00","url":"https://junglewise.ai/threats/cve-2026-91765-cleanup-xml-node-in-the-soap-xml-parser-recurses-once-per-xml"},{"cve":"CVE-2026-6103","cvss":4.3,"slug":"cve-2026-6103-phar-tar-number-parses-the-octal-size-field-of-a-tar-header-into-a","title":"PHP Phar TAR integer overflow in size parsing","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:23.79+00:00","url":"https://junglewise.ai/threats/cve-2026-6103-phar-tar-number-parses-the-octal-size-field-of-a-tar-header-into-a"},{"cve":"CVE-2026-17545","slug":"cve-2026-17545-on-windows-php-s-filesystem-and-stream-apis-do-not-reject","title":"PHP filesystem and stream APIs reserved device name handling","severity":"info","exploited":false,"published_at":"2026-09-25T21:17:23.253+00:00","url":"https://junglewise.ai/threats/cve-2026-17545-on-windows-php-s-filesystem-and-stream-apis-do-not-reject"},{"cve":"CVE-2025-14181","cvss":6.5,"slug":"cve-2025-14181-the-soap-http-client-guards-its-response-buffer-growth-with-a","title":"PHP SOAP HTTP client heap buffer overflow in response parsing","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:19.84+00:00","url":"https://junglewise.ai/threats/cve-2025-14181-the-soap-http-client-guards-its-response-buffer-growth-with-a"},{"cve":"CVE-2026-93682","cvss":5.8,"slug":"cve-2026-93682-when-the-http-stream-wrapper-follows-a-redirect-and-the-response","title":"PHP HTTP stream wrapper out-of-bounds read in redirect handling","severity":"medium","exploited":false,"published_at":"2026-09-25T20:17:47.597+00:00","url":"https://junglewise.ai/threats/cve-2026-93682-when-the-http-stream-wrapper-follows-a-redirect-and-the-response"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"PHPMailer","slug":"phpmailer","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/phpmailer"}],"technology":{"hub":true,"name":"Php","slug":"php-php","vendor":{"name":"PHP","slug":"php","url":"https://junglewise.ai/threats/vendors/php"},"aliases":[],"category":"language-runtime","description":"Server-side scripting language and runtime for web development.","url":"https://junglewise.ai/threats/technologies/php-php"},"most_severe":[{"cve":"CVE-2026-91765","cvss":7.5,"slug":"cve-2026-91765-cleanup-xml-node-in-the-soap-xml-parser-recurses-once-per-xml","title":"PHP SOAP XML parser unbounded recursion denial of service","severity":"high","exploited":false,"published_at":"2026-09-25T21:17:24.55+00:00","url":"https://junglewise.ai/threats/cve-2026-91765-cleanup-xml-node-in-the-soap-xml-parser-recurses-once-per-xml"},{"cve":"CVE-2026-91767","cvss":6.5,"slug":"cve-2026-91767-php-openssl-matches-wildcard-name-in-ext-openssl-xp-ssl-c","title":"PHP OpenSSL heap-buffer overflow in wildcard certificate name matching","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:24.793+00:00","url":"https://junglewise.ai/threats/cve-2026-91767-php-openssl-matches-wildcard-name-in-ext-openssl-xp-ssl-c"},{"cve":"CVE-2025-14181","cvss":6.5,"slug":"cve-2025-14181-the-soap-http-client-guards-its-response-buffer-growth-with-a","title":"PHP SOAP HTTP client heap buffer overflow in response parsing","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:19.84+00:00","url":"https://junglewise.ai/threats/cve-2025-14181-the-soap-http-client-guards-its-response-buffer-growth-with-a"},{"cve":"CVE-2026-92842","cvss":5.9,"slug":"cve-2026-92842-the-convert-base64-encode-convert-quoted-printable-encode-and","title":"PHP stream filter heap information leak with NUL bytes in line-break-chars","severity":"medium","exploited":false,"published_at":"2026-09-25T22:18:49.943+00:00","url":"https://junglewise.ai/threats/cve-2026-92842-the-convert-base64-encode-convert-quoted-printable-encode-and"},{"cve":"CVE-2026-91766","cvss":5.9,"slug":"cve-2026-91766-when-the-http-stream-wrapper-follows-a-redirect-it-forwards-the","title":"PHP HTTP stream wrapper credential leak on cross-origin redirect","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:24.673+00:00","url":"https://junglewise.ai/threats/cve-2026-91766-when-the-http-stream-wrapper-follows-a-redirect-it-forwards-the"},{"cve":"CVE-2026-93682","cvss":5.8,"slug":"cve-2026-93682-when-the-http-stream-wrapper-follows-a-redirect-and-the-response","title":"PHP HTTP stream wrapper out-of-bounds read in redirect handling","severity":"medium","exploited":false,"published_at":"2026-09-25T20:17:47.597+00:00","url":"https://junglewise.ai/threats/cve-2026-93682-when-the-http-stream-wrapper-follows-a-redirect-and-the-response"},{"cve":"CVE-2026-91769","cvss":4.3,"slug":"cve-2026-91769-php-s-openssl-stream-peer-verification-checks-the-certificate-s","title":"PHP OpenSSL stream peer verification certificate validation bypass","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:24.913+00:00","url":"https://junglewise.ai/threats/cve-2026-91769-php-s-openssl-stream-peer-verification-checks-the-certificate-s"},{"cve":"CVE-2026-6103","cvss":4.3,"slug":"cve-2026-6103-phar-tar-number-parses-the-octal-size-field-of-a-tar-header-into-a","title":"PHP Phar TAR integer overflow in size parsing","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:23.79+00:00","url":"https://junglewise.ai/threats/cve-2026-6103-phar-tar-number-parses-the-octal-size-field-of-a-tar-header-into-a"},{"cve":"CVE-2026-17545","slug":"cve-2026-17545-on-windows-php-s-filesystem-and-stream-apis-do-not-reject","title":"PHP filesystem and stream APIs reserved device name handling","severity":"info","exploited":false,"published_at":"2026-09-25T21:17:23.253+00:00","url":"https://junglewise.ai/threats/cve-2026-17545-on-windows-php-s-filesystem-and-stream-apis-do-not-reject"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}