PT-2026-39448 · Php+3 · Php+3

·

CVE-2026-7261

·

Published

2026-05-07

·

Updated

2026-07-06

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions 8.2.0 through 8.2.30 PHP versions 8.3.0 through 8.3.30 PHP versions 8.4.0 through 8.4.20 PHP versions 8.5.0 through 8.5.5
Description When SoapServer is configured with SOAP PERSISTENCE SESSION, the handler object is persisted across requests using session storage. If a SOAP request results in an error, the persistence is handled incorrectly, causing the object to be freed while a pointer to it remains. This leads to a use-after-free condition, which is a situation where a program continues to use a pointer after it has been freed, potentially resulting in memory corruption, information disclosure, or process crashes.
Recommendations Update PHP version 8.2.x to 8.2.31 Update PHP version 8.3.x to 8.3.31 Update PHP version 8.4.x to 8.4.21 Update PHP version 8.5.x to 8.5.6

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:33449
ALSA-2026:34354
BDU:2026-08445
BIT-LIBPHP-2026-7261
BIT-PHP-2026-7261
BIT-PHP-MIN-2026-7261
CVE-2026-7261
OESA-2026-2342
OESA-2026-2343
OESA-2026-2344
OESA-2026-2420
OESA-2026-2421
OPENSUSE-SU-2026:10747-1
RHSA-2026:33449
RHSA-2026:34354
USN-8336-1
USN-8513-1

Affected Products

Linuxmint
Php
Rocky Linux
Ubuntu