Severity
5.3MEDIUM
EPSS
0.1%
top 84.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 13
Latest updateMar 16
Description
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.2 | Impact: 1.4
Affected Packages10 packages
🔴Vulnerability Details
5📋Vendor Advisories
21Red Hat
▶
GitLab▶
CVE-2025-11246: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could h↗2026-01-09
Cisco▶
Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities↗2025-11-05