In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.
| Vendor | Product | Versions |
|---|---|---|
| php | php | 8.4.*, 8.5.* |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| oracle | solaris | cert_advisory | 90% |
Updated vendor to PHP Group, changed severity to HIGH, set CVSS estimate to 7.5, and marked the vulnerability as actively exploited.
Initial creation