CVE-2023-0662
published 2023-02-16CVE-2023-0662: In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.41%
70.9th percentile
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | php7.4 | < php7.4 7.4.33-1+deb11u3 (bullseye) | php7.4 7.4.33-1+deb11u3 (bullseye) |
| debian | php8.2 | < php7.4 7.4.33-1+deb11u3 (bullseye) | php7.4 7.4.33-1+deb11u3 (bullseye) |
| msrc | azl3_php_8.3.19-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_php_8.1.16-1_on_cbl_mariner_2.0 | — | — |
| php | php | >= 8.0.0 < 8.0.28 | 8.0.28 |
| php | php | >= 8.1.0 < 8.1.16 | 8.1.16 |
| php | php | >= 8.2.0 < 8.2.3 | 8.2.3 |
| php_group | php | >= 8.0.x < 8.0.28 | 8.0.28 |
| php_group | php | >= 8.1.x < 8.1.16 | 8.1.16 |
| php_group | php | >= 8.2.x < 8.2.3 | 8.2.3 |
| react | http | >= 0.8.0 < 1.9.0 | 1.9.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_ubuntu7.7HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Festo Didactic SE MES PC
cisa_ics·2026-01-27·CVSS 7.5
[HIGH] Festo Didactic SE MES PC
ICS Advisory
##
Festo Didactic SE MES PC
Release DateJanuary 27, 2026
Alert CodeICSA-26-027-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
The
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (PHP) — CVE-2023-0662
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2023-0662 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (PHP) — CVE-2023-0662
Oracle Oracle Communications Applications Risk Matrix: Core (PHP) vulnerability
CVE: CVE-2023-0662
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2023-03-02·CVSS 2.3
CVE-2023-0568 [LOW] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled certain gzip files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2022-31628)
It was discovered that PHP incorrectly handled certain cookies.
An attacker could possibly use this issue to compromise data integrity.
(CVE-2022-31629)
It was discovered that PHP incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2022-31631)
It was discovered that PHP incorrectly handled resolving long paths. A
remote attacker could possibly use this issue to obtain or modify sensitive
information. (CVE-2023-0568)
It was discovered that PHP incorrectly handled a large number of
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2023-02-28·CVSS 7.7
CVE-2023-0568 [HIGH] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled certain invalid Blowfish
password hashes. An invalid password hash could possibly allow applications
to accept any password as valid, contrary to expectations. (CVE-2023-0567)
It was discovered that PHP incorrectly handled resolving long paths. A
remote attacker could possibly use this issue to obtain or modify sensitive
information. (CVE-2023-0568)
It was discovered that PHP incorrectly handled a large number of parts in
HTTP form uploads. A remote attacker could possibly use this issue to cause
PHP to consume resources, leading to a denial of service. (CVE-2023-0662)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
php: DoS vulnerability when parsing multipart request body
vendor_redhat·2023-02-15·CVSS 7.5
CVE-2023-0662 [HIGH] CWE-400 php: DoS vulnerability when parsing multipart request body
php: DoS vulnerability when parsing multipart request body
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.
A vulnerability was found in PHP. This security flaw occurs when the request body parsing in PHP allows any unauthenticated attacker to consume a large amount of CPU time and trigger excessive logging. A large amount of CPU time required for processing requests can block all available worker processes and significantly delay or slow the processing of legitimate user requests. The large volume of warning messages can wear down the disk and fill i
Microsoft
DoS vulnerability when parsing multipart request body
vendor_msrc·2023-02-14·CVSS 7.5
CVE-2023-0662 [HIGH] CWE-400 DoS vulnerability when parsing multipart request body
DoS vulnerability when parsing multipart request body
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
php: php
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.micro
Debian
CVE-2023-0662: php7.4 - In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessiv...
vendor_debian·2023·CVSS 7.5
CVE-2023-0662 [HIGH] CVE-2023-0662: php7.4 - In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessiv...
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.
Scope: local
bullseye: resolved (fixed in 7.4.33-1+deb11u3)
GHSA
ReactPHP's HTTP server continues parsing unused multipart parts after reaching input field and file upload limits
ghsa·2023-05-17·CVSS 7.5
CVE-2023-26044 [HIGH] CWE-400 ReactPHP's HTTP server continues parsing unused multipart parts after reaching input field and file upload limits
ReactPHP's HTTP server continues parsing unused multipart parts after reaching input field and file upload limits
### Summary
Previous versions of ReactPHP's HTTP server component contain a potential DoS vulnerability that can cause high CPU load when processing large HTTP request bodies. This vulnerability has little to no impact on the default configuration, but can be exploited when explicitly using the `RequestBodyBufferMiddleware` with very large settings. This might lead to consuming large amounts of CPU time for processing requests and significantly delay or slow down the processing of legitimate user requests.
### Patches
The supplied patch resolves this vulnerability for ReactPHP.
### Workarounds
- Keeping the request body limit using `RequestBodyBufferMiddleware` sensible w
OSV
ReactPHP's HTTP server continues parsing unused multipart parts after reaching input field and file upload limits
osv·2023-05-17·CVSS 7.5
CVE-2023-26044 [HIGH] ReactPHP's HTTP server continues parsing unused multipart parts after reaching input field and file upload limits
ReactPHP's HTTP server continues parsing unused multipart parts after reaching input field and file upload limits
### Summary
Previous versions of ReactPHP's HTTP server component contain a potential DoS vulnerability that can cause high CPU load when processing large HTTP request bodies. This vulnerability has little to no impact on the default configuration, but can be exploited when explicitly using the `RequestBodyBufferMiddleware` with very large settings. This might lead to consuming large amounts of CPU time for processing requests and significantly delay or slow down the processing of legitimate user requests.
### Patches
The supplied patch resolves this vulnerability for ReactPHP.
### Workarounds
- Keeping the request body limit using `RequestBodyBufferMiddleware` sensible w
OSV
php7.0 vulnerabilities
osv·2023-03-02·CVSS 5.5
CVE-2022-31628 [MEDIUM] php7.0 vulnerabilities
php7.0 vulnerabilities
It was discovered that PHP incorrectly handled certain gzip files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2022-31628)
It was discovered that PHP incorrectly handled certain cookies.
An attacker could possibly use this issue to compromise data integrity.
(CVE-2022-31629)
It was discovered that PHP incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2022-31631)
It was discovered that PHP incorrectly handled resolving long paths. A
remote attacker could possibly use this issue to obtain or modify sensitive
information. (CVE-2023-0568)
It was discovered that PHP incorrectly handled a large number of field and file
parts in HTTP form uploads. A remote atta
OSV
php7.2, php7.4, php8.1 vulnerabilities
osv·2023-02-28·CVSS 6.2
CVE-2023-0567 [MEDIUM] php7.2, php7.4, php8.1 vulnerabilities
php7.2, php7.4, php8.1 vulnerabilities
It was discovered that PHP incorrectly handled certain invalid Blowfish
password hashes. An invalid password hash could possibly allow applications
to accept any password as valid, contrary to expectations. (CVE-2023-0567)
It was discovered that PHP incorrectly handled resolving long paths. A
remote attacker could possibly use this issue to obtain or modify sensitive
information. (CVE-2023-0568)
It was discovered that PHP incorrectly handled a large number of parts in
HTTP form uploads. A remote attacker could possibly use this issue to cause
PHP to consume resources, leading to a denial of service. (CVE-2023-0662)
OSV
CVE-2023-0662: In PHP 8
osv·2023-02-16·CVSS 7.5
CVE-2023-0662 [HIGH] CVE-2023-0662: In PHP 8
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-16
Published