Back

LOW

NULL pointer dereference in SOAP apache:Map decoder with missing <value>

Published May 10, 2026

Description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.

Affected products

Remediation

Red Hat statement

To exploit this issue, a remote unauthenticated attacker needs to send a malicious request to be processed by the apache:Map decoder, causing a crash in the PHP SOAP server process. Due to this reason, this vulnerability has been rated with an important severity.

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner php
Published May 10, 2026
Updated Jul 15, 2026
Reserved Apr 28, 2026
CISA Vulnrichment
Updated May 11, 2026
NVD
Status Modified
Modified Jul 24, 2026
Red Hat
Severity Important
Public date May 10, 2026