BIT-php-2026-91765

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/php/BIT-php-2026-91765.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-php-2026-91765
Aliases
Published
2026-10-01T09:34:06Z
Modified
2026-10-01T10:11:17Z
Summary
SOAP: Unbounded Recursion in Server-Side cleanup_xml_node
Details

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"
    ],
    "severity":  "High"
}
References

Affected packages

Bitnami / php

Package

Name
php
Purl
pkg:bitnami/php

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.2.0
Fixed
8.2.34
Introduced
8.3.0
Fixed
8.3.35
Introduced
8.4.0
Fixed
8.4.26
Introduced
8.5.0
Fixed
8.5.11

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/php/BIT-php-2026-91765.json"