CVE-2026-91767
EUVD-2026-8734325.09.2026, 21:17
php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| php | php | 8.2.* ≤ 𝑥 < 8.2.34 | CNA |
| php | php | 8.3.* ≤ 𝑥 < 8.3.35 | CNA |
| php | php | 8.4.* ≤ 𝑥 < 8.4.26 | CNA |
| php | php | 8.5.* ≤ 𝑥 < 8.5.11 | CNA |
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| php5 |
| ||||||||
| php7.0 |
| ||||||||
| php7.2 |
| ||||||||
| php7.4 |
| ||||||||
| php8.1 |
| ||||||||
| php8.3 |
| ||||||||
| php8.5 |
|
Vulnerability Media Exposure