Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.5

CVE-2026-6722: PHP SOAP Extension Remote Code Execution in Certain Versions

CVE-2026-6722
Summary

A vulnerability in PHP's SOAP extension affects certain versions. It allows an attacker to execute malicious code on a server by manipulating SOAP requests. To fix this, update to a supported version of PHP.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
php php >= 8.2.0, < 8.2.31
>= 8.3.0, < 8.3.31
>= 8.4.0, < 8.4.21
>= 8.5.0, < 8.5.6
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Original title
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global...
Original description
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.
nvd CVSS4.0 9.5
Vulnerability type
CWE-416 Use After Free
Published: 10 May 2026 · Updated: 30 May 2026 · First seen: 10 May 2026