NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix
Published Jul 13, 2025
5.9
MEDIUMCVSS 3.1
EPSS 0.98%
Description
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.
Affected products
-
Affected
- ≥ 8.1.*, < 8.1.33
- ≥ 8.2.*, < 8.2.29
- ≥ 8.3.*, < 8.3.23
- ≥ 8.4.*, < 8.4.10
No data.
Red Hat Enterprise Linux 8
php:7.4-8100020260119075152.f7998665
Fixed · RHSA-2026:2470
Red Hat Enterprise Linux 8
php:8.2-8100020260106091451.f7998665
Fixed · RHSA-2026:1412
Red Hat Enterprise Linux 9
php:8.2-9070020260107073439.9
Fixed · RHSA-2026:1409
Red Hat Enterprise Linux 9
php:8.3-9070020251002063832.9
Fixed · RHSA-2025:23309
Red Hat Enterprise Linux 10
php
Fix deferred
Red Hat Enterprise Linux 6
php
Fix deferred
Red Hat Enterprise Linux 7
php
Fix deferred
Red Hat Enterprise Linux 9
php
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | php:7.4-8100020260119075152.f7998665 | Fixed | RHSA-2026:2470 |
| Red Hat Enterprise Linux 8 | php:8.2-8100020260106091451.f7998665 | Fixed | RHSA-2026:1412 |
| Red Hat Enterprise Linux 9 | php:8.2-9070020260107073439.9 | Fixed | RHSA-2026:1409 |
| Red Hat Enterprise Linux 9 | php:8.3-9070020251002063832.9 | Fixed | RHSA-2025:23309 |
| Red Hat Enterprise Linux 10 | php | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | php | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | php | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | php | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Currently, no mitigation is currently available for this vulnerability.
References (8)
- http://www.openwall.com/lists/oss-security/2025/07/11/4
- https://access.redhat.com/security/cve/CVE-2025-6491 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2378690 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21276 Advisory
- https://github.com/php/php-src/security/advisories/GHSA-453j-q27h-5p8x exploitVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/07/msg00017.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-6491
- https://www.cve.org/CVERecord?id=CVE-2025-6491
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data