HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-7263 — In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() meth...

·Source: NIST NVD

Updated:

Executive Summary

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

Analysis

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application. CVSS Score: 7.5. Published: 2026-05-10T06:16:08.343.

Indicators of Compromise (1)

CVE (1)
CVE-2026-7263
Source Attribution

Originally published by NIST NVD on May 10, 2026. Verified by: NIST.

Related Threats