CVE-2025-6491

Updated: 2025-08-20 03:17:09.242822

Description:

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x MEDIUM 5.9

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU php 8.0.30 5.9 MEDIUM Released CLSA-2026:1769686676 2026-01-29 13:17:33
Alpine Linux 3.18 ELS php 8.2.16 5.9 MEDIUM Needs Triage 2026-02-11 10:02:58
CentOS 6 ELS php 5.3.3 5.9 MEDIUM Released CLSA-2025:1753780501 2025-08-09 01:43:50
CentOS 7 ELS php 5.4.16 5.9 MEDIUM Released CLSA-2025:1754384758 2025-08-20 05:19:06
CentOS 8.4 ELS php 7.4.6 5.9 MEDIUM Released CLSA-2025:1753793859 2025-07-30 01:50:20
CentOS 8.5 ELS php 7.4.19 5.9 MEDIUM Released CLSA-2025:1753798945 2025-07-30 01:50:21
CentOS Stream 8 ELS php 7.2.24 5.9 MEDIUM Released CLSA-2025:1753465703 2025-07-26 04:17:24
CloudLinux 6 ELS php 5.3.3 5.9 MEDIUM Ignored 2025-07-16 04:45:23 Out of support scope
CloudLinux 7 ELS php 5.4.16 5.9 MEDIUM Released CLSA-2025:1754385801 2025-08-19 00:18:55
Debian 10 ELS php 7.3 5.9 MEDIUM Needs Triage 2026-02-11 10:02:40
Total: 17