CVE-2025-14181

EUVD-2025-211004
The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller than the data it then writes into it, producing a heap buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
phpCNA
6.5 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
phpphp
8.2.* ≤
𝑥
< 8.2.34
CNA
phpphp
8.3.* ≤
𝑥
< 8.3.35
CNA
phpphp
8.4.* ≤
𝑥
< 8.4.26
CNA
phpphp
8.5.* ≤
𝑥
< 8.5.11
CNA
Debian logo
Debian Releases
Debian Product
Codename
php8.2
bookworm
vulnerable
bookworm (security)
vulnerable
php8.4
forky
vulnerable
sid
vulnerable
trixie
vulnerable
trixie (security)
8.4.26-1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php5
jammy
dne
noble
dne
resolute
dne
trusty
needs-triage
php7.0
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage
php7.2
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne
php7.4
focal
needs-triage
jammy
dne
noble
dne
resolute
dne
php8.1
jammy
needs-triage
noble
dne
resolute
dne
php8.3
jammy
dne
noble
needs-triage
resolute
dne
php8.5
jammy
dne
noble
dne
resolute
needs-triage