PT-2025-52599 · Php+6 · Php+6

·

CVE-2025-14180

·

Published

2025-01-01

·

Updated

2026-07-07

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PHP versions 8.1.0 through 8.1.33 PHP versions 8.2.0 through 8.2.29 PHP versions 8.3.0 through 8.3.28 PHP versions 8.4.0 through 8.4.15 PHP versions 8.5.0
Description When using the PDO PostgreSQL driver with PDO::ATTR EMULATE PREPARES enabled, an invalid character sequence in a prepared statement parameter may cause the PQescapeStringConn() function to return NULL. This leads to a null pointer dereference within the pdo parse params() function, which can result in a segmentation fault and cause a denial of service by crashing the target server.
Recommendations Update to version 8.1.34 or later. Update to version 8.2.30 or later. Update to version 8.3.29 or later. Update to version 8.4.16 or later. Update to version 8.5.1 or later. As a temporary mitigation, disable the PDO::ATTR EMULATE PREPARES setting when using the PDO PostgreSQL driver.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:1409
ALSA-2026:1412
ALSA-2026:1429
ALSA-2026:1628
AZL-73201
AZL-73234
BDU:2026-00449
BIT-LIBPHP-2025-14180
BIT-PHP-2025-14180
BIT-PHP-MIN-2025-14180
CVE-2025-14180
DSA-6088-1
GHSA-8XR5-QPPJ-GVWJ
MGASA-2025-0330
OESA-2026-1022
OESA-2026-1023
OESA-2026-1024
OESA-2026-1025
OPENSUSE-SU-2025:15837-1
OPENSUSE-SU-2026:20113-1
RHSA-2026:1169
RHSA-2026:1185
RHSA-2026:1187
RHSA-2026:1190
RHSA-2026:1409
RHSA-2026:1412
RHSA-2026:1429
RHSA-2026:1628
RHSA-2026:7614
SUSE-SU-2026:0071-1
SUSE-SU-2026:0086-1
SUSE-SU-2026:20146-1
USN-7953-1

Affected Products

Alt Linux
Debian
Linuxmint
Php
Red Os
Rocky Linux
Ubuntu