CVE-2026-17545

EUVD-2026-87329
On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
phpCNA
6.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
phpphp
8.2.* ≤
𝑥
< 8.2.34
CNA
phpphp
8.3.* ≤
𝑥
< 8.3.35
CNA
phpphp
8.4.* ≤
𝑥
< 8.4.26
CNA
phpphp
8.5.* ≤
𝑥
< 8.5.11
CNA
Debian logo
Debian Releases
Debian Product
Codename
php8.2
bookworm
8.2.32-1~deb12u1
fixed
bookworm (security)
8.2.33-1~deb12u1
fixed
php8.4
forky
8.4.24-1
fixed
sid
8.4.24-1
fixed
trixie
8.4.24-1~deb13u1
fixed
trixie (security)
8.4.24-1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php5
jammy
dne
noble
dne
resolute
dne
trusty
needs-triage
php7.0
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage
php7.2
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne
php7.4
focal
needs-triage
jammy
dne
noble
dne
resolute
dne
php8.1
jammy
needs-triage
noble
dne
resolute
dne
php8.3
jammy
dne
noble
needs-triage
resolute
dne
php8.5
jammy
dne
noble
dne
resolute
needs-triage