AZL-104919

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104919.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-104919
Upstream
  • CVE-2026-91765
Published
2026-09-25T21:17:24Z
Modified
2026-09-27T05:34:32Z
Summary
CVE-2026-91765 affecting package php 8.3.33-1
Details

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.

References

Affected packages

Azure Linux:3 / php

Package

Name
php
Purl
pkg:rpm/azure-linux/php

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
8.3.33-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104919.json"