A type confusion vulnerability in the mergeparam() function of phphttp_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2.5.6"
},
{
"introduced": "3.0.0"
},
{
"last_affected": "3.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.0-rc1"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7398.json"
"2026-04-11T05:00:46Z"
[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"131021496443385898743292904032294007741",
"91232038910744409217388444223265266793",
"261318667876175873601489787703585171531",
"167123906585228430315616853570800366652"
]
},
"source": "https://github.com/m6w6/ext-http/commit/17137d4ab1ce81a2cee0fae842340a344ef3da83",
"id": "CVE-2016-7398-1d33e960",
"signature_type": "Line",
"target": {
"file": "src/php_http_params.c"
}
}
]