Back

MEDIUM

DoS attack via DOMNode::C14N()

Published May 10, 2026

Description

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

Affected products

Remediation

Red Hat statement

To exploit this issue, an attacker needs to be able to supply specially crafted XML data to be processed by the `DOMNode::C14N()` method. This can trigger an infinite loop, causing excessive resource consumption, eventually resulting in a denial of service in the program processing the data. As this flaw allows an unauthenticated and remote attacker to cause a denial of service, it has been rated with an important severity.

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner php
Published May 10, 2026
Updated Jul 15, 2026
Reserved Apr 28, 2026
CISA Vulnrichment
Updated May 11, 2026
NVD
Status Modified
Modified Jul 24, 2026
Red Hat
Severity Important
Public date May 10, 2026