CVE-2025-6491 Information

Description

In PHP versions:8.1. before 8.1.33 8.2. before 8.2.29 8.3. before 8.3.23 8.4. before 8.4.10 when parsing XML data in SOAP extensions overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.

Reference

https://github.com/php/php-src/security/advisories/GHSA-453j-q27h-5p8x

CNNVD-202507-1791 (Published: 2025-07-13)

Share on: