<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 13:27:02 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-7261 — SoapServer session-persisted object use-after-free via SOAP header fault</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-7261</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PHP Group PHP&lt;/p&gt;
&lt;p&gt;In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PHP Group PHP&lt;/p&gt;
&lt;p&gt;In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-7261</guid>
    </item>
    <item>
      <title>USN-8336-1 — php8.1, php8.3, php8.4, php8.5 vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8336-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: php8.1, Ubuntu:24.04:LTS: php8.3, Ubuntu:25.10: php8.4, Ubuntu:26.04:LTS: php8.5&lt;/p&gt;
&lt;p&gt;Aleksey Solovev and Nikita Sveshnikov discovered that PHP improperly
handled NUL bytes when preparing SQL queries in the PDO Firebird driver. An
attacker could possibly use this issue to perform SQL injection attacks.
(CVE-2025-14179)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled certain encoding names in
mbstring. An attacker could possibly use this issue to obtain sensitive
information or cause a denial of service. This issue only affected Ubuntu
25.10 and Ubuntu 26.04 LTS. (CVE-2026-6104)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled object references while
parsing crafted SOAP requests. A remote attacker could possibly use this
issue to execute arbitrary code. (CVE-2026-6722)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly sanitized certain data in the
PHP-FPM status page. A remote attacker could possibly use this issue to
inject arbitrary JavaScript code. (CVE-2026-6735)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP had an encoding mismatch in mbstring. An
attacker could possibly use this issue to cause PHP to crash, resulting in
a denial of service. (CVE-2026-7259)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled SOAP session persistence
after errors. A remote attacker could possibly use this issue to obtain
sensitive information or cause PHP to crash, resulting in a denial of
service. (CVE-2026-7261)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled missing values in SOAP
typemap decoding. A remote attacker could possibly use this issue to cause
PHP to crash, resulting in a denial of service.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: php8.1, Ubuntu:24.04:LTS: php8.3, Ubuntu:25.10: php8.4, Ubuntu:26.04:LTS: php8.5&lt;/p&gt;
&lt;p&gt;Aleksey Solovev and Nikita Sveshnikov discovered that PHP improperly
handled NUL bytes when preparing SQL queries in the PDO Firebird driver. An
attacker could possibly use this issue to perform SQL injection attacks.
(CVE-2025-14179)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled certain encoding names in
mbstring. An attacker could possibly use this issue to obtain sensitive
information or cause a denial of service. This issue only affected Ubuntu
25.10 and Ubuntu 26.04 LTS. (CVE-2026-6104)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled object references while
parsing crafted SOAP requests. A remote attacker could possibly use this
issue to execute arbitrary code. (CVE-2026-6722)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly sanitized certain data in the
PHP-FPM status page. A remote attacker could possibly use this issue to
inject arbitrary JavaScript code. (CVE-2026-6735)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP had an encoding mismatch in mbstring. An
attacker could possibly use this issue to cause PHP to crash, resulting in
a denial of service. (CVE-2026-7259)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled SOAP session persistence
after errors. A remote attacker could possibly use this issue to obtain
sensitive information or cause PHP to crash, resulting in a denial of
service. (CVE-2026-7261)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled missing values in SOAP
typemap decoding. A remote attacker could possibly use this issue to cause
PHP to crash, resulting in a denial of service.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8336-1</guid>
    </item>
  </channel>
</rss>
