DoS attack via DOMNode::C14N()
Published May 10, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.63%
Description
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.
Affected products
-
- Version 8.4.*StatusaffectedConstraints<8.4.21
- Version 8.5.*StatusaffectedConstraints<8.5.6
- Version
No data.
Red Hat Enterprise Linux 10
php8.4-0:8.4.21-1.el10_2
Fixed · RHSA-2026:22649
Red Hat Enterprise Linux 10
php
Not affected
Red Hat Enterprise Linux 6
php
Not affected
Red Hat Enterprise Linux 7
php
Not affected
Red Hat Enterprise Linux 8
php:7.4/php
Not affected
Red Hat Enterprise Linux 8
php:8.2/php
Not affected
Red Hat Enterprise Linux 9
php
Not affected
Red Hat Enterprise Linux 9
php:8.2/php
Not affected
Red Hat Enterprise Linux 9
php:8.3/php
Not affected
Red Hat Hardened Images
php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | php8.4-0:8.4.21-1.el10_2 | Fixed | RHSA-2026:22649 |
| Red Hat Enterprise Linux 10 | php | Not affected | n/a |
| Red Hat Enterprise Linux 6 | php | Not affected | n/a |
| Red Hat Enterprise Linux 7 | php | Not affected | n/a |
| Red Hat Enterprise Linux 8 | php:7.4/php | Not affected | n/a |
| Red Hat Enterprise Linux 8 | php:8.2/php | Not affected | n/a |
| Red Hat Enterprise Linux 9 | php | Not affected | n/a |
| Red Hat Enterprise Linux 9 | php:8.2/php | Not affected | n/a |
| Red Hat Enterprise Linux 9 | php:8.3/php | Not affected | n/a |
| Red Hat Hardened Images | php | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit this issue, an attacker needs to be able to supply specially crafted XML data to be processed by the `DOMNode::C14N()` method. This can trigger an infinite loop, causing excessive resource consumption, eventually resulting in a denial of service in the program processing the data. As this flaw allows an unauthenticated and remote attacker to cause a denial of service, it has been rated with an important severity.
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
References (7)
- https://access.redhat.com/errata/RHSA-2026:22649
- https://access.redhat.com/security/cve/CVE-2026-7263 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468572 Issue Tracking
- https://github.com/php/php-src/security/advisories/GHSA-4jhr-8w89-j733 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-7263
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7263.json
- https://www.cve.org/CVERecord?id=CVE-2026-7263
Change history (0)
No recorded changes yet.