<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T18:17:17.707077+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-7262</id>
    <title>CVE-2026-7262 — NULL pointer dereference in SOAP apache:Map decoder with missing &lt;value&gt;</title>
    <updated>2026-10-10T18:17:17.729688+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PHP Group PHP, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Hardened Images</p>
<p>In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-7262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/usn-8336-1</id>
    <title>USN-8336-1 — php8.1, php8.3, php8.4, php8.5 vulnerabilities</title>
    <updated>2026-10-10T18:17:17.729761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: php8.1, Ubuntu:24.04:LTS: php8.3, Ubuntu:25.10: php8.4, Ubuntu:26.04:LTS: php8.5</p>
<p>Aleksey Solovev and Nikita Sveshnikov discovered that PHP improperly
handled NUL bytes when preparing SQL queries in the PDO Firebird driver. An
attacker could possibly use this issue to perform SQL injection attacks.
(CVE-2025-14179)</p>
<p>It was discovered that PHP incorrectly handled certain encoding names in
mbstring. An attacker could possibly use this issue to obtain sensitive
information or cause a denial of service. This issue only affected Ubuntu
25.10 and Ubuntu 26.04 LTS. (CVE-2026-6104)</p>
<p>It was discovered that PHP incorrectly handled object references while
parsing crafted SOAP requests. A remote attacker could possibly use this
issue to execute arbitrary code. (CVE-2026-6722)</p>
<p>It was discovered that PHP incorrectly sanitized certain data in the
PHP-FPM status page. A remote attacker could possibly use this issue to
inject arbitrary JavaScript code. (CVE-2026-6735)</p>
<p>It was discovered that PHP had an encoding mismatch in mbstring. An
attacker could possibly use this issue to cause PHP to crash, resulting in
a denial of service. (CVE-2026-7259)</p>
<p>It was discovered that PHP incorrectly handled SOAP session persistence
after errors. A remote attacker could possibly use this issue to obtain
sensitive information or cause PHP to crash, resulting in a denial of
service. (CVE-2026-7261)</p>
<p>It was discovered that PHP incorrectly handled missing values in SOAP
typemap decoding. A remote attacker could possibly use this issue to cause
PHP to crash, resulting in a denial of service.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/usn-8336-1"/>
  </entry>
</feed>
