NULL pointer dereference in SOAP apache:Map decoder with missing <value>
Published May 10, 2026
2.9
LOWCVSS 4.0
EPSS 1.05%
Description
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element. This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.
Affected products
-
- Version 8.2.*StatusaffectedConstraints<8.2.31
- Version 8.3.*StatusaffectedConstraints<8.3.31
- Version 8.4.*StatusaffectedConstraints<8.4.21
- Version 8.5.*StatusaffectedConstraints<8.5.6
- Version
No data.
Red Hat Enterprise Linux 10
php-0:8.3.31-1.el10_2
Fixed · RHSA-2026:23388
Red Hat Enterprise Linux 10
php8.4-0:8.4.21-1.el10_2
Fixed · RHSA-2026:22649
Red Hat Enterprise Linux 8
php:7.4-8100020260604072603.f7998665
Fixed · RHSA-2026:34354
Red Hat Enterprise Linux 8
php:8.2-8100020260521052503.f7998665
Fixed · RHSA-2026:22305
Red Hat Enterprise Linux 9
php-0:8.0.30-6.el9_8
Fixed · RHSA-2026:33449
Red Hat Enterprise Linux 9
php:8.2-9080020260521080715.9
Fixed · RHSA-2026:22143
Red Hat Enterprise Linux 9
php:8.3-9080020260521113736.9
Fixed · RHSA-2026:22142
Red Hat Enterprise Linux 6
php
Not affected
Red Hat Enterprise Linux 7
php
Not affected
Red Hat Hardened Images
php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | php-0:8.3.31-1.el10_2 | Fixed | RHSA-2026:23388 |
| Red Hat Enterprise Linux 10 | php8.4-0:8.4.21-1.el10_2 | Fixed | RHSA-2026:22649 |
| Red Hat Enterprise Linux 8 | php:7.4-8100020260604072603.f7998665 | Fixed | RHSA-2026:34354 |
| Red Hat Enterprise Linux 8 | php:8.2-8100020260521052503.f7998665 | Fixed | RHSA-2026:22305 |
| Red Hat Enterprise Linux 9 | php-0:8.0.30-6.el9_8 | Fixed | RHSA-2026:33449 |
| Red Hat Enterprise Linux 9 | php:8.2-9080020260521080715.9 | Fixed | RHSA-2026:22143 |
| Red Hat Enterprise Linux 9 | php:8.3-9080020260521113736.9 | Fixed | RHSA-2026:22142 |
| Red Hat Enterprise Linux 6 | php | Not affected | n/a |
| Red Hat Enterprise Linux 7 | php | Not affected | n/a |
| Red Hat Hardened Images | php | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit this issue, a remote unauthenticated attacker needs to send a malicious request to be processed by the apache:Map decoder, causing a crash in the PHP SOAP server process. Due to this reason, this vulnerability has been rated with an important severity.
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/AU:Y/RE:M/U:Amber
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:Amber
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed May 11, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
May-Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 1.05% (0.01047) | 62.98th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.45% (0.00450) | 35.55th | v5 (v2026.06.15) |
| May 10, 2026 | 0.11% (0.00108) | 28.62th | v4 (v2025.03.14) |
References (13)
- https://access.redhat.com/errata/RHSA-2026:22142
- https://access.redhat.com/errata/RHSA-2026:22143
- https://access.redhat.com/errata/RHSA-2026:22305
- https://access.redhat.com/errata/RHSA-2026:22649
- https://access.redhat.com/errata/RHSA-2026:23388
- https://access.redhat.com/errata/RHSA-2026:33449
- https://access.redhat.com/errata/RHSA-2026:34354
- https://access.redhat.com/security/cve/CVE-2026-7262 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468565 Issue Tracking
- https://github.com/php/php-src/security/advisories/GHSA-hmxp-6pc4-f3vv vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-7262
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7262.json
- https://www.cve.org/CVERecord?id=CVE-2026-7262
Change history (0)
No recorded changes yet.