CVE-2026-7260
published 2026-07-30CVE-2026-7260: Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.*…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.11%
1.7th percentile
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | php8.4 | — | — |
| devspaces | code-rhel9 | — | — |
| php | php | — | — |
| php | php | >= 8.2.0 < 8.2.33 | 8.2.33 |
| php | php | >= 8.3.0 < 8.3.33 | 8.3.33 |
| php | php | >= 8.4.0 < 8.4.24 | 8.4.24 |
| php | php | >= 8.5.0 < 8.5.9 | 8.5.9 |
| php_7.4 | php | — | — |
| php_8.2 | php | — | — |
| php_8.3 | php | — | — |
| php_group | php | >= 8.2.* < 8.2.33 | 8.2.33 |
| php_group | php | >= 8.3.* < 8.3.33 | 8.3.33 |
| php_group | php | >= 8.4.* < 8.4.24 | 8.4.24 |
| php_group | php | >= 8.5.* < 8.5.9 | 8.5.9 |
| rhoai | odh-workbench-codeserver-datascience-cpu-py312-rhel9 | — | — |
| ubuntu | php7.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv4.05.4MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_ubuntu9.8CRITICAL
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2026-09-07·CVSS 9.8
CVE-2026-7260 [CRITICAL] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: PHP could be made to crash or expose sensitive information if it received
specially crafted input.
It was discovered that PHP incorrectly handled Apache map decoding in SOAP
servers with a typemap configured. A remote attacker could use this issue
to cause a NULL pointer dereference, resulting in a denial of service.
(CVE-2026-7262)
It was discovered that PHP incorrectly handled signed integer overflow in
the metaphone() function. An attacker could use this issue to cause an
out-of-bounds read, resulting in a denial of service. (CVE-2026-7568)
It was discovered that PHP incorrectly handled circular symbolic links in
phar archives. An attacker could use this issue to cause unbounded
recursion, resulting in a denial of service. (CVE-2026-7260)
It was
Red Hat
php: PHP: Denial of Service via circular symbolic links in phar archives
vendor_redhat·2026-07-30·CVSS 5.5
CVE-2026-7260 [MEDIUM] CWE-606 php: PHP: Denial of Service via circular symbolic links in phar archives
php: PHP: Denial of Service via circular symbolic links in phar archives
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
A flaw was found in PHP. When processing a specially crafted PHP Archive (phar) file containing circular symbolic links, the PHP process can enter an uncontrolled loop. This unbounded recursion exhausts the program's memory stack, causing the PHP application to crash. This vulnerability could allow an attacker to trigger a Denial of Service (DoS) condition, making the affected PHP service unavailable.
Statement: This Moderate impact flaw in PHP allows a local attacker
VulDB
PHP Group up to 8.2.32/8.3.32/8.4.23/8.5.8 phar recursion (EUVD-2026-51092 / Nessus ID 338335)
vuldb·2026-08-21·CVSS 5.5
CVE-2026-7260 [MEDIUM] PHP Group up to 8.2.32/8.3.32/8.4.23/8.5.8 phar recursion (EUVD-2026-51092 / Nessus ID 338335)
A vulnerability classified as problematic has been found in PHP Group PHP up to 8.2.32/8.3.32/8.4.23/8.5.8. This impacts an unknown function of the component phar. Performing a manipulation results in uncontrolled recursion.
This vulnerability is cataloged as CVE-2026-7260. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-30
Published