CVE-2026-7260
EUVD-2026-5109230.07.2026, 12:19
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| php | php | 8.2.* ≤ 𝑥 < 8.2.33 | CNA |
| php | php | 8.3.* ≤ 𝑥 < 8.3.33 | CNA |
| php | php | 8.4.* ≤ 𝑥 < 8.4.24 | CNA |
| php | php | 8.5.* ≤ 𝑥 < 8.5.9 | CNA |
Debian Releases
Common Weakness Enumeration