CVE-2026-17544
EUVD-2026-5109130.07.2026, 12:17
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| php | php | 8.4.* ≤ 𝑥 < 8.4.24 | CNA |
| php | php | 8.5.* ≤ 𝑥 < 8.5.9 | CNA |
Debian Releases
Common Weakness Enumeration