CVE-2026-7258

Source
https://cve.org/CVERecord?id=CVE-2026-7258
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-7258.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-7258
Aliases
Downstream
AZL (1)
BELL (1)
CGA (2)
CLSA (9)
DEBIAN (1)
MGASA (1)
MINI (4)
OESA (5)
openSUSE (2)
RHSA (8)
RLSA (7)
SUSE (5)
UBUNTU (1)
Related
Published
2026-05-10T04:28:14Z
Modified
2026-08-12T03:30:33Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/U:Amber CVSS Calculator
Summary
Out-of-bounds read in urldecode() on NetBSD
Details

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.

Database specific
{
    "cna_assigner": "php",
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7258.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "8.2.*"
                },
                {
                    "fixed": "8.2.31"
                },
                {
                    "introduced": "8.3.*"
                },
                {
                    "fixed": "8.3.31"
                },
                {
                    "introduced": "8.4.*"
                },
                {
                    "fixed": "8.4.21"
                },
                {
                    "introduced": "8.5.*"
                },
                {
                    "fixed": "8.5.6"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "8.2.31"
                },
                {
                    "fixed": "8.3.31"
                },
                {
                    "fixed": "8.4.21"
                },
                {
                    "fixed": "8.5.6"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/php/php-src

Affected ranges

Type
GIT
Repo
https://github.com/php/php-src
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.2.0"
        },
        {
            "fixed": "8.2.21"
        }
    ],
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-7258.json"