SoapServer session-persisted object use-after-free via SOAP header fault
Published May 10, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.53%
Description
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.
Affected products
-
- Version 8.2.*StatusaffectedConstraints<8.2.31
- Version 8.3.*StatusaffectedConstraints<8.3.31
- Version 8.4.*StatusaffectedConstraints<8.4.21
- Version 8.5.*StatusaffectedConstraints<8.5.6
- Version
No data.
Red Hat Enterprise Linux 10
php-0:8.3.31-1.el10_2
Fixed · RHSA-2026:23388
Red Hat Enterprise Linux 10
php8.4-0:8.4.21-1.el10_2
Fixed · RHSA-2026:22649
Red Hat Enterprise Linux 8
php:7.4-8100020260604072603.f7998665
Fixed · RHSA-2026:34354
Red Hat Enterprise Linux 8
php:8.2-8100020260521052503.f7998665
Fixed · RHSA-2026:22305
Red Hat Enterprise Linux 9
php-0:8.0.30-6.el9_8
Fixed · RHSA-2026:33449
Red Hat Enterprise Linux 9
php:8.2-9080020260521080715.9
Fixed · RHSA-2026:22143
Red Hat Enterprise Linux 9
php:8.3-9080020260521113736.9
Fixed · RHSA-2026:22142
Red Hat Enterprise Linux 6
php
Out of support scope
Red Hat Enterprise Linux 7
php
Affected
Red Hat Enterprise Linux 8
php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | php-0:8.3.31-1.el10_2 | Fixed | RHSA-2026:23388 |
| Red Hat Enterprise Linux 10 | php8.4-0:8.4.21-1.el10_2 | Fixed | RHSA-2026:22649 |
| Red Hat Enterprise Linux 8 | php:7.4-8100020260604072603.f7998665 | Fixed | RHSA-2026:34354 |
| Red Hat Enterprise Linux 8 | php:8.2-8100020260521052503.f7998665 | Fixed | RHSA-2026:22305 |
| Red Hat Enterprise Linux 9 | php-0:8.0.30-6.el9_8 | Fixed | RHSA-2026:33449 |
| Red Hat Enterprise Linux 9 | php:8.2-9080020260521080715.9 | Fixed | RHSA-2026:22143 |
| Red Hat Enterprise Linux 9 | php:8.3-9080020260521113736.9 | Fixed | RHSA-2026:22142 |
| Red Hat Enterprise Linux 6 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | php | Affected | n/a |
| Red Hat Enterprise Linux 8 | php | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw only affects PHP users who have configured their runtime with the `SOAP_PERSISTENCE_SESSION` option which is not enabled by default. This flaw can lead to memory corruption, information disclosure, or service crashes. Normally, a SOAP server will only handle one SOAP request per PHP request, so it's unlikely that the attacker will be able to control the freed memory segment. Red Hat systems also employ address space layout randomization (ASLR) which makes accessing freed memory segments improbable.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (5)
- https://access.redhat.com/security/cve/CVE-2026-7261 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468563 Issue Tracking
- https://github.com/php/php-src/security/advisories/GHSA-m33r-qmcv-p97q vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-7261
- https://www.cve.org/CVERecord?id=CVE-2026-7261
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-7261 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2468563 | Issue Tracking | |
| https://github.com/php/php-src/security/advisories/GHSA-m33r-qmcv-p97q | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-7261 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-7261 |
Change history (0)
No recorded changes yet.