By vendor
Php vulnerabilities
Known CVEs affecting Php products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-14355MEDIUM 5.6
PHP versions before specific patch levels contain a flaw in how they allocate memory for AES key-wrap-with-padding operations within the OpenSSL extension. When processing encrypted keys, the application reserves too little memory for the output, allowing OpenSSL to write beyond these bounds. This corrupts internal heap structures and causes the application to crash. The vulnerability requires specific conditions to trigger—it is not a remote code execution—but does enable a network attacker to cause denial of service on affected systems.